macOS Standalone Installation
End-user walkthrough of the standalone AI Endpoint Shield installer on macOS, including the security prompts users are asked to approve.
Overview
This page covers the standalone installer on macOS — the .pkg a user runs by hand, rather than a fleet-wide MDM rollout. It walks through the installation flow of AI Endpoint Shield and the permissions users may be prompted to approve, so you can share it with end users ahead of time.
Steps Guide
Run the Installer
Double-click the AI Endpoint Shield .app file to launch it. This opens the installer wizard.
Installer Wizard – Introduction Screen
The installer wizard launches.

The introduction screen explains:
What AI Endpoint Shield does
The installation location (user directory)
That no root or administrator permissions are required
Click Continue to proceed.
Installation Type Confirmation

Click Install to begin installation.
This screen confirms:
Disk space required
Installation scope (current user only)
Target disk (e.g., Macintosh HD)
Folder Access Permissions (Optional)
After installation, AI Endpoint Shield may request permission to access specific folders in the user’s home directory:
Desktop
Documents
Downloads



These permissions are used to:
Scan MCP-related files
Validate configurations
Monitor relevant artifacts within the user environment
User Choice:
Allow – Enables folder-level scanning
Don’t Allow – Skips access to that folder
After installation
Confirm the agent is running:
/usr/local/bin/akto-endpoint-shield --version
/usr/local/bin/akto-endpoint-shield check-config --path ~/.akto-endpoint-shield/config
launchctl list | grep akto-endpoint-shieldcheck-config should print provisioned, and both LaunchAgents should show a PID rather than -. If either check fails, see macOS Troubleshooting.
Related documentation
Last updated

