Desired-state controls declared once and evaluated on a 15-minute pull/report cycle — the original family (firewall, disk encryption, service, package) plus the config/compliance family: browser extension block/allow/force via managed-policy files, screen lock (sysadminctl / HKLM / dconf system-locks), password policy (pwpolicy / secedit / pwquality+faillock), login banners, remote-services disable, guest and auto-login off, auto-updates, Gatekeeper/SmartScreen, and firewall hardening. Assignment precedence is device over tag over all, drift can auto-remediate, and per-control compliance rolls up fleet-wide. Where macOS won't let an agent enforce a setting, the policy generates a .mobileconfig hard-lock — CMS-signed with plain openssl (any org cert with its chain: OV/EV TLS, S/MIME, or code-signing), so it installs green as Verified; agent-only controls are omitted from the profile.