Before you start, make sure you have:
- A macOS host (macOS 15 Sequoia or later) that you can sign in to as an admin.
- The Origin agent
.pkginstaller — download from the console under Settings → Installers. - A provisioning token — create one under Settings → Provisioning Tokens.
Installation steps
1
Launch the installer
Double-click the
.pkg you downloaded. macOS opens the standard Installer app.Click Continue.2
Confirm the install location
The installer shows the disk it will install to (typically Macintosh HD) and the approximate disk-space footprint.Click Install.
3
Authenticate to install
macOS prompts for your admin password to allow the installer to write to system locations.Enter your password and click Install Software.
4
Paste the registration token
After the package extracts, the Origin Agent Registration dialog appears. Paste the provisioning token you copied from the console.Click Register.
5
Allow the installer to control System Events
The installer needs to drive System Events to finish wiring the agent into the OS.Click Allow when macOS asks for permission.
6
Grant Full Disk Access
The agent prompts you to grant Full Disk Access so it can read application logs and detect AI tooling installed in user-scoped locations.Click OK. macOS opens System Settings → Privacy & Security → Full Disk Access.
- Click the + button at the bottom of the list.
- Navigate to
/Applicationsand select Origin.app. - Click Open, then toggle the row on.
7
Confirm background activity
macOS posts a notification confirming the agent is allowed to run in the background.You’re done. The agent is now reporting in. Open the Origin console — your host should appear under Settings → Endpoint Inventory within a minute.
Origin collects AI event data at the application layer, through each AI tool’s OpenTelemetry exporter and through application-level hooks. There is no proxy to approve and no certificate to trust, so the install involves no network-extension or certificate-trust prompts.For fleet deployments, a single privacy-preferences (PPPC) profile pushed by MDM pre-approves Full Disk Access and removes the prompt in step 6 entirely — see MDM Overview.