> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy Agent Hub with SimpleMDM

> Create a least-privilege SimpleMDM API key and confirm your SAML-mapped email attribute so Cimento can deploy the endpoint agent to a device group.

Cimento authenticates to SimpleMDM with an API key, uploads the agent package and configuration profile, pairs them with a device group you choose through an assignment group, pushes the install, and tracks it per device.

## Prerequisites

* A SimpleMDM custom attribute that holds each device user's email address. SimpleMDM has no built-in email variable, so the profile substitutes a custom attribute you name. For a trustworthy mapping, populate it from your identity provider during SAML-authenticated (Automated) enrollment. Manually or API-populated attributes work but are best-effort and can be blank or spoofed.
* A device group to use as the pilot target.

## Steps

<Steps>
  <Step title="Confirm the email attribute">
    In SimpleMDM, open **Settings › Custom Attributes** and note the exact name of the attribute that holds the user email, for example `email`. Cimento does not create it.
  </Step>

  <Step title="Create an API key">
    Open **Settings › API** and create a key for Cimento with exactly the permissions in the table below. Set every other resource to **none**.
  </Step>

  <Step title="Enter the values in Cimento">
    Under **Admin → Integrations → AI agents → SimpleMDM**, enter the attribute name exactly as it appears in SimpleMDM, then paste the API key. The key is stored encrypted per tenant and never shown again. If the attribute name does not match, SimpleMDM substitutes nothing and devices report unattributed.
  </Step>

  <Step title="Verify">
    Cimento makes read-only calls to confirm the key works and to list your device groups.
  </Step>

  <Step title="Deploy">
    Choose a device group. Cimento uploads the signed `.pkg` as an app and the `.mobileconfig` as a custom configuration profile with attribute support enabled, pairs both with the group through an assignment group, and pushes the install. Nothing is pushed until you click **Deploy**. The page then tracks install status per device.
  </Step>
</Steps>

## Permissions to set and why

### Set to write

| Resource | Purpose |
| - | - |
| Apps | Uploads the agent package and updates it in place on each release. |
| Assignment Groups | Pairs the app and profile with the device group you deploy to. |
| Custom Configuration Profiles | Installs the profile carrying the agent's configuration. |

### Set to read

| Resource | Purpose |
| - | - |
| Account | Confirms the key works before the deployment runs. |
| Device Groups | Lists the groups you pick a deployment target from. |
| Devices | Lists the Macs in that group so the rollout can be reported per device. |
| Installed Apps | Reads how much of the group has the agent installed. |

### Needed only to disconnect

| Resource | Purpose |
| - | - |
| Scripts, write | Stores the uninstall script and runs it as a job. |
| Devices, raised from read to write | Runs that uninstall job against the devices in the group. |

If a permission is missing, Cimento names the specific one to grant, so you can start with this set.

## Disconnecting

**Disconnect** in Cimento runs the uninstall script against the targeted devices, removes the app, profile and assignment group Cimento created, and then deletes the stored key.
