Generating enrollment codes and viewing device data requires a workspace
admin. The agent currently supports macOS.
Enroll
1
Get a one-time code
In the web app, open AI Usage in the sidebar, select the person the
device belongs to, and click Add this device. The dialog shows a
one-time enrollment code with its expiry, plus the exact commands for the
remaining steps — copy them from there.
2
Install the agent binary
Run the install one-liner from the dialog on the device. It places the
kelasa-agent binary on the machine.3
Enroll with the code
As your normal user (not sudo), run the enroll command from the dialog:This exchanges the one-time code for a device credential stored locally.
Codes are single-use and expire, so generate a fresh one if it lapses.
4
Install the background service
5
Grant Full Disk Access (macOS)
In System Settings → Privacy & Security → Full Disk Access, enable
the
kelasa-agent binary. Without it the browser and Claude-config
collectors report “permission denied” coverage instead of data — the agent
still runs, and the device page shows the gap honestly.Claude Code usage — configured automatically
The agent runs a local, loopback-only telemetry receiver and merges the five required telemetry settings into the device’s~/.claude/settings.json,
leaving every other key untouched. Claude Code usage starts flowing with no
manual setup, and uninstall removes exactly those keys again.
Revoke or remove
- Revoke a device from its device page in the web app — its credential stops working immediately and it can no longer check in.
-
Uninstall on the machine itself:
This removes the background service and reverts the Claude Code telemetry settings the agent added.