Components
Data flow
1
An agent fires a hook event
Cursor, Claude Code or Codex invokes the hook with the event payload on stdin. The hook keeps only the allowlisted fields described in What data is collected and appends the result to
~/.cimento/telemetry.ndjson.2
The drain runs
Every five minutes, and once at login, the scheduler starts the drain. On macOS this is the LaunchAgent
ai.cimento.telemetry.drain; on Windows, a per-user scheduled task.3
Identity is resolved
The drain stamps each event with the user email from the MDM-managed source. The hook never writes identity, so a spoofed hook payload cannot attribute events to someone else.
4
Events are posted
The drain POSTs to
https://api.cimento.ai/api/agent-hub/telemetry/events in server-capped chunks. Delivery is at-least-once and the server de-duplicates on event ID. On a network error, proxy failure, 429 or 5xx it leaves the buffer in place and backs off until the next run.Identity resolution
The drain resolvesuser_email in fixed order and never trusts the hook payload for it:
- MDM-managed value. macOS: the forced managed preference
user_emailin theai.cimento.telemetrydomain, delivered by the configuration profile. Windows: the machine-policy registry valueHKLM\SOFTWARE\Policies\Cimento\telemetry\user_email, or the signed-in user’s UPN when no explicit value is set. - Identity file written by the installer:
/Library/Application Support/Cimento/identity.jsonon macOS,%PROGRAMDATA%\Cimento\identity.jsonon Windows. - Unattributed. Events still ship, carrying the device serial in place of an email, and show in the dashboard as an unattributed device.
Where the hook is registered
If a managed location cannot be written, the installer falls back to the per-user file so the device still reports.
Fail-open by design
The hook always exits 0 and always returns an allow response to permission-style hooks, including on malformed input, an unwritable disk, or an internal error. It never blocks, slows or alters what the coding agent does. Setting the environment variableCIMENTO_TELEMETRY_DISABLED=1 disables the hook, the drain and the reconcile.
Updates and removal
- Updates. On each release Cimento updates the package in place in your MDM, so devices upgrade through the same assignment without anyone re-uploading anything.
- Removal. Clicking Disconnect on the integration runs an uninstall across the targeted devices and removes the objects Cimento created in your MDM before deleting the stored credential.
Code signing
- macOS. The
.pkgis signed and notarized. - Windows. The hook, the drain and the install and uninstall scripts are Authenticode-signed through Azure Artifact Signing with an RFC 3161 timestamp. The signing certificate rotates daily, so do not pin its thumbprint. For WDAC or signature-based detection rules, pin the durable identity EKU
1.3.6.1.4.1.311.97.707736870.60106188.709977328.172420691.
Windows install details
Binaries install toC:\ProgramData\Cimento\bin. The installer writes its log to C:\ProgramData\Cimento\logs\install.log, and the detection value Intune checks is the registry string HKLM\SOFTWARE\Cimento\Telemetry\Version. Installation needs an interactive user session because the scheduled task and Cursor’s per-user hook configuration are created in that session; if Intune installs at the login screen the installer exits nonzero and Intune retries later.