rdmbair15m5-changelog-20260823-2346-setapp-brew-fleet-licensing-policy
Fleet Policy: Setapp Application Lifecycle and Homebrew Cask Coordination
Author: agent@rdmbair15m5
Date: 2026-08-23 23:46 EDT
Target: Fleetwide (rdmsm4x,
rdmbair13m5, rdmbair15m5,
rdmpw3265m, rdmpw3275m,
jdmbair13m5)
Topic:
fleet-policy-setapp-vs-brew-licensing
1. Summary & Core Directive
Across all fleet Macs, never install standalone Homebrew
casks for applications that are installed and licensed under
Setapp in /Applications/Setapp/ (e.g.,
cleanmymac, downie, forklift,
permute, gemini-macpaw,
shortcutie).
The Conflict
- Setapp Architecture: Applications installed via
Setapp reside in
/Applications/Setapp/, have bundle identifiers with-setappsuffixes (e.g.com.macpaw.CleanMyMac-setapp,com.binarynights.forklift-setapp), and authenticate licensing dynamically through the Setapp desktop daemon (com.setapp.DesktopClient). - Homebrew Standalone Casks: Homebrew casks for these
products download direct retail vendor binaries to
/Applications/. These retail binaries require independent vendor serial keys or direct individual subscriptions, and will not activate using a Setapp subscription. - Collision Risk: Adopting or installing standalone casks causes dual-install confusion, overwrites app associations, and breaks user licensing.
2. Canonical Fleet Standard
Manage Setapp Itself via Homebrew:
- Install/adopt the Setapp desktop client cask:
brew install --cask --adopt setapp - Setapp will handle background updates and license enforcement for all member applications.
- Install/adopt the Setapp desktop client cask:
Exclude Setapp Member Apps from Standalone Homebrew Casks:
- The following casks must remain UNINSTALLED in
brew list --caskon any host using Setapp for these tools:cleanmymacdownieforkliftpermuteshortcutie- Any other Setapp library app installed in
/Applications/Setapp/
- The following casks must remain UNINSTALLED in
Cask Audit Rule for Fleet Agents:
- When running app inventory scans or
brew install --cask --adoptaudits, check if the app exists under/Applications/Setapp/or has a bundle ID ending in-setapp. - If an app is Setapp-managed, skip standalone cask adoption and
ensure only
setappcask is tracked.
- When running app inventory scans or
Hybrid / Account-Login Apps (
Paste.app):- For applications like
Pastethat support multiple auth mechanisms (App Store IAP, direct vendor login, and Setapp sign-in), ensure the binary matches the desired license source. If adopted into Brew, verify the direct build authenticates with the user's Setapp/Paste credentials.
- For applications like