Skip to content
Discuss your AI plans 

Compliance reporting for Apple fleets.

DARE Technology · reporting and compliance for the Apple devices they manage

An Apple-focused managed service provider knew the state of every machine it looked after and had no way to show a customer any of it. We built the reporting layer over that data, and the compliance model behind the figure their customers now read.

The Zappl dashboard: alerts across the fleet, each with the number of devices behind it, from compliance under 50% to machines that have stopped checking in

Overview

DARE Technology manage Apple devices for their customers, on open-source tooling they had built around Munki with their own command-line agent distributing packages. The tooling did its job on the machines themselves and stopped there, because the agent wrote its output on the device and nothing stood between that output and a customer who wanted to know whether their laptops were patched.

OpenKit built Zappl, the reporting and compliance layer over the data that agent was already producing, and the first thing DARE could put in front of a customer.

  • A customer portal with device and application views, dashboards, alerts and scheduled PDF reporting by email.
  • A management portal where DARE run every client, generate per-client tokens, and step into a customer’s own view to fix a problem.
  • A compliance model worked out with DARE, so the figure a customer sees reflects how their devices are actually being run.

100+

customer organisations on the platform, each able to see their own devices without an engineer in the middle.

£1,000+

a month against the tooling their customers were paying for before, in many cases.

2

portals reading one set of numbers, one for DARE’s customers and one for their own engineers.

14 days

The eligibility window, applied at both device and application level.

Challenge

What DARE needed

Every conversation with a prospective client ended in the same place. How many of our machines are patched? Which ones are behind? Can we have that monthly? The honest answer was that the information existed on each device and nowhere else, so the brief went wider than a dashboard and started with what had to be true before any dashboard would mean anything:

  • A customer has to be able to see their own devices, without an engineer in the middle.
  • The compliance figure has to mean something, or nobody will act on it.
  • DARE’s engineers need one place to run every client, or the operational cost eats the margin.

Approach

How compliance is measured

The first thing we worked out with DARE was the maths behind the figure. Pass-or-fail compliance treats a machine with one application a version behind exactly like a machine nobody has touched since spring, and a fleet scored that way tells its owner nothing they can act on.

Pass-or-fail scoring

One out-of-date application anywhere on a machine and the whole machine counts as non-compliant. Nothing else about its state matters.

A device three months out of contact scores exactly the same as a device that finished updating this morning.

Every fleet reads as broken, including the ones being managed well, so the number stops being something anyone acts on.

Averaged and eligible scoring

Compliance averaged across a device’s applications, so a machine most of the way there reads as most of the way there.

An eligibility layer on top. A device counts towards the measure only if it completed a successful full update inside the window.

A Last Compliant Date written by the agent on every run, with rules for exactly when it moves. Letting a prompted application close moves it, and deferring the prompt leaves it where it is.

The eligibility window is fourteen days, specified with the client, written into the agent and applied at both device and application level.

The build

The two portals

One record a support engineer can work from

Serial number, disk space, FileVault status, the full application list with versions and install paths, and the agent log with automatic purging. The engineer stops asking the customer to read things off their screen.

Per-device drill-down with the hardware details, disk space and policy posture for one machine

Every figure links to the devices behind it

Application counts and compliance figures are clickable throughout, filtering straight to the devices they describe. The fleet view answers "which ones?" without anyone exporting a spreadsheet to find out.

Application catalogue with version tracking and compliance detail across the device fleet

The client-management layer

DARE’s engineers create a client, generate that client’s bearer token, and keep licence keys and expiry dates against the record. When a customer hits a problem, an engineer can step into that customer’s own view of Zappl, see exactly what they are seeing, and fix it from there.

Admin view listing the customer organisations, their device counts and compliance
  • The build: Customer portal, Client management portal, Compliance calculation model, Per-client bearer tokens, Scheduled PDF reporting, React + TypeScript.
  • OpenKit certifications: ISO 27001, ISO 9001 (UKAS-accredited), Cyber Essentials.
  • Controls on this project: UK GDPR, UK data residency.

ISO 27001, ISO 9001 and Cyber Essentials are OpenKit certifications, and we operate to UK GDPR. The controls listed are the ones set on this project.

Result

What changed for DARE

DARE’s customers sign in to Zappl and read the state of their own machines. OpenKit has maintained the platform since it launched, keeping patch coverage and the compliance rules current.

Both figures on this page come from DARE. Their director gives the customer count, and the saving is what their customers report against the tooling they paid for before.

Voice

What DARE said

OpenKit transformed our business requirements into Zappl, an elegant web application that provides secure Apple patch management for our customers. Their process began with thorough discovery sessions, demonstrating a clear understanding of our business objectives and user needs. The intuitive interface and streamlined workflows have reduced our staff admin workload and increased user adoption, with 100+ customers already onboarded. Throughout the partnership, OpenKit consistently demonstrated their commitment to delivering business value, from initial planning through to final implementation.
Michael · Director, DARE Technology
OpenKit delivered us a high-performance React application for Apple patch management, featuring large data ingestion and processing with enterprise-grade security. Their technical expertise was evident in every aspect, from an optimised frontend architecture to a robust backend with comprehensive API integration. The resulting application excels in both performance and reliability, with comprehensive monitoring and an automated deployment pipeline ensuring system stability.
Anthony, Technical Director at DARE Technology

Other engagements

What could your business do with AI?

Find out with experts who become part of your team. We uncover opportunities, get ideas working, and help your people build on the results. We reply within one working day.

Get in touch  AI Engineering