For everyone · Guide · 4 min

Roll out the desktop recorder: IT and MDM guide

For IT: downloads, app identity, network access, macOS permissions and the PPPC profile to deploy Scalign Assistant with MDM.

This guide is for IT administrators rolling out the Scalign desktop recorder to a team. It covers what the app does, where to get it, which permissions it needs and what you can pre-approve with MDM. Setting it up on your own computer? See Install the desktop recorder.

What it is

Scalign Assistant is the desktop app that records meetings for Scalign. It detects when Zoom, Google Meet or Microsoft Teams starts a call and records it, or records an in-person meeting through the computer's microphone.

  • It records audio only: the user's microphone and the other participants' audio. It never captures the screen and never asks for screen recording permission.
  • macOS 13 Ventura or later, on Apple silicon (M1 or later). Intel Macs aren't supported.
  • Windows 10 or later, 64-bit.

Download

  • macOS: https://github.com/Scalign/desktop-releases/releases/latest/download/Scalign-Assistant.dmg
  • Windows: https://github.com/Scalign/desktop-releases/releases/latest/download/Scalign-Assistant-Setup.exe

Users can also download it in Scalign under Settings → Recording → Desktop recorder.

App identity (macOS)

  • Name: Scalign Assistant
  • Bundle ID: com.scalign.desktop
  • Team ID: PZY49ZZN8C
  • Signed with a Developer ID certificate, hardened runtime, and notarized by Apple.

To check a copy yourself, run codesign -dv --verbose=2 "/Applications/Scalign Assistant.app" and look for the bundle ID and TeamIdentifier.

Install

macOS

The DMG contains the app; it belongs in /Applications. Deploy the .app there with your MDM, or let users drag it across. Updates only work from /Applications: started from Downloads or the disk image, the app asks to be moved.

Windows

The installer is a standard NSIS installer (not one-click). The user picks whether to install for themselves or for all users, and can change the install folder. By default it installs for the current user under %LOCALAPPDATA%\Programs\Scalign Assistant.

Updates and network access

The app updates itself from the Scalign/desktop-releases repository on GitHub: it checks shortly after launch and then every 30 minutes, downloads new versions in the background and installs them when the app restarts. Allow outbound HTTPS to:

  • github.com
  • objects.githubusercontent.com

If these are blocked, the app keeps working but stops updating.

macOS permissions

On first launch the app walks the user through four permissions, in this order. Recording pauses if any of them is later turned off.

  • Accessibility: to detect when Zoom, Meet or Teams starts a call, and who is speaking. No other apps are read.
  • Full Disk Access: to read the meeting link of Microsoft Teams meetings, and of Google Meet in Safari, which macOS keeps behind Full Disk Access. Without it, those recordings can't be matched to calendar events.
  • Microphone: to record the user's side of the conversation.
  • System audio recording: to record what the other participants say.

Pre-approve permissions with MDM

A Privacy Preferences Policy Control (PPPC) profile can pre-approve Accessibility and Full Disk Access, so users skip those two steps. Create one entry for the app:

  • Identifier: com.scalign.desktop, identifier type Bundle ID
  • Code requirement: identifier "com.scalign.desktop" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "PZY49ZZN8C"
  • Services: Accessibility (Accessibility) and Full Disk Access (SystemPolicyAllFiles), both set to Allow.

To print the code requirement from an installed copy, run codesign -dr - "/Applications/Scalign Assistant.app".

Microphone and system audio recording can't be granted through MDM: macOS only lets the user allow them, so each user clicks Allow once during setup. MDM can only deny them.

Optionally, add a Notifications payload for com.scalign.desktop so the app's "Meeting detected" prompts show without asking.

Windows

There's nothing to pre-approve through MDM on Windows. Make sure Windows privacy settings let desktop apps use the microphone (Settings → Privacy & security → Microphone).

After installing

Each user opens the app, clicks Sign in and signs in with their Scalign account. In Scalign, Settings → Recording → Desktop recorder then shows "Signed in and ready to record", or that microphone or system audio access is missing.

Questions from your security review? Email support@scalign.ai, or see our security overview and sub-processors.

Questions? Email Scalign, or ask Scalign directly in Claude or ChatGPT.