Add a macOS Disk management declaration profile that sets ExternalStorage to ReadOnly, and create a manual label "Macs excluded from external storage restrictions" for opt-outs. Register the new label in default.yml and reference the new Disk management settings.json in the workstations fleet controls, excluding hosts in the manual label so they retain read-write external storage. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes **New Features** - Enforces external storage devices as read-only on macOS, Windows, and Linux systems - Introduces new host labels allowing administrators to selectively exempt specific devices from external storage restrictions <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Welcome to Fleet
Introduction
The Fleet handbook is the living source of truth for how we run the company. This handbook is open to the world and feedback and contributions are welcome from everyone. Feel free to click "Edit this page" to suggest an improvement anywhere you see fit. (The right reviewer will be automatically notified, and will reply to you promptly. Your change will go live on the website ≈10 minutes after it is merged.)