Machine policy
Decide updates, telemetry, sync, AI, voice, local agents, auto-lock and the RDP printer for every user of a computer.
Where the policy file lives#
A JSON file in an administrator-owned location decides settings for every user of the computer:
| Platform | Path |
|---|---|
| Linux | /etc/ravelon/policy.json |
| macOS | /Library/Application Support/Ravelon/policy.json |
| Windows | %ProgramData%\Ravelon\policy.json |
Only administrators should be able to write the file and its folder. Ravelon reads it once at startup, so restart Ravelon after a change.
Example#
Every field is optional. A field that is present is enforced; a missing field leaves the choice to the user.
json
{
"updates": { "automatic": false, "check": true },
"telemetry": { "enabled": false },
"sync": { "enabled": true, "server": "https://sync.example.com" },
"autoLock": { "maxMinutes": 15 },
"ai": { "enabled": false },
"voice": { "enabled": false },
"agents": { "enabled": false },
"rdpPrinter": { "enabled": false }
}Fields#
| Field | Effect |
|---|---|
| updates.check: false | Ravelon never contacts the update server. Use your software distribution. |
| updates.automatic: false | Updates are offered but never installed without a click. |
| telemetry.enabled: false | No usage statistics are collected or sent. |
| sync.enabled: false | No sign-in and no sync. Vaults stay on the device. |
| sync.server | Sign-in and sync only with this https server. |
| autoLock.maxMinutes | Vaults protected by a passphrase lock after at most this many idle minutes (1 to 240). |
| ai.enabled: false | AI providers, the Ravelon Agent and # command suggestions are off. |
| voice.enabled: false | Voice is off and its button is hidden. |
| agents.enabled: false | Local AI coding agents are off. |
| rdpPrinter.enabled: false | RDP sessions never offer the redirected Ravelon printer. |
Settings decided by the policy show a Managed badge. Settings → About → Diagnostics shows the file in use.
Important: Invalid files fail closed. Unknown or misspelled keys, wrong types or out-of-range values reject the whole file. Ravelon then turns off updates, telemetry, sync, AI, Voice, local agents and the RDP printer, and shows the error under Settings → About → Diagnostics until the file is fixed.
Last updated 30 September 2026