How it works
One Mac shows the dashboard. Every other Mac runs a small client that reports to it, over an encrypted connection that only paired Macs can open.
A dashboard, and a client on each Mac
SystemStatusRemote, the host
Runs on the Mac you look at. Shows the dashboard, lists the Macs being watched, accepts pairing requests and stores history. It lives in the menu bar too, so it keeps listening and recording with its window closed.
SystemStatusClient, the client
Runs on each Mac you want to watch, as a menu-bar item with no window. It connects out to the host, samples what the host asks for, and reports once per interval.
Clients dial out to the host, so only the host needs to accept incoming connections.
From download to dashboard
You need macOS 15 (Sequoia) or later on every Mac, and the Macs must reach each other over the network. Download both apps first.
Open the host
Open SystemStatusRemote on the Mac that will show the dashboard. When macOS asks to accept incoming connections, choose Allow. The bottom of the sidebar should say "Listening on port 47,820".
Add Client… shows the name clients will see it under, and its address, and starts taking pairing requests (for 15 minutes, or the time chosen in Settings).
Open the client and request pairing
Open SystemStatusClient on the Mac you want to watch, then click its menu-bar item. Hosts on the same network are listed under Host by their Mac's name. For a host on another network, choose Enter an Address and type its address and port 47820.
Click Request Pairing. The client shows a check phrase of three words and waits.
Accept on the host
Whenever it suits you, find the request under Pairing Requests at the top of the host's sidebar (the menu-bar item shows a count). Click Accept…, check that the host shows the same three words, and accept.
The client then shows the words again: click Yes, Pair if they're the ones the host showed. It connects, and the Mac appears in the sidebar with a green dot.
First launch prompts. Each app keeps its identity key in the Keychain, so macOS asks once: choose Always Allow. A client may also ask to find devices on your local network: choose Allow (or turn it on later in System Settings › Privacy & Security › Local Network).
Three words that prove it's really your Mac
When a client asks to pair, both Macs show the same check phrase, made from both Macs' certificates:
maple · river · copper
If the words match, accept on the host and confirm on the client. If they differ, deny the request: something else on the network may be posing as one of the Macs. A denied client is turned away for 15 minutes.
A machine in the middle sees different certificates on each side, so the two Macs would show different words. Its chance of faking a match is one in 16.7 million per attempt, and the host and the client each stop a request that keeps starting over, so it gets very few attempts.
- No rush: a request waits as long as the client keeps asking, up to a day.
- Prefer a code? Pair with a code instead gives a one-time code to type on the client.
- Choose in the host's Settings how long it takes requests: Off, 15 minutes, 1, 4 or 8 hours, or Always.
images/screenshots/pairing-accept.png
Private by design
Your Macs talk only to each other. There's no account to make and no service in the middle.
Encrypted both ways
Every connection uses TLS 1.3 with mutual authentication: the client checks the host, and the host checks the client. Nothing is accepted before both sides are authenticated, and every message is size-limited and validated.
Pinned after pairing
Pairing pins each side's certificate, so afterwards only the paired Macs can connect. Each app keeps its identity key in the Keychain. Remove a client on the host and it can't connect again until paired anew.
Found isn't trusted
Seeing a host on the network doesn't make it trusted; accepting the request and comparing the words does. Once paired, a client recognizes its host by certificate, so it keeps connecting even if the host's address or name changes.
Sandboxed and notarized
Both apps run in the macOS App Sandbox with only the entitlements they need, and every release is signed with a Developer ID and notarized by Apple. History stays inside the app's container, protected by FileVault.
Built for watching many Macs
- Overview shows several Macs side by side. Click one for a full-size view.
- Order: drag Macs up and down the sidebar. The Overview follows.
- Compare Macs: Command- or Shift-click Macs, then choose By Mac or By Module.
- The gear on a Mac's panel sets its modules, how often it samples, and whether it's in the Overview.
- Not responding, then Offline: quiet Macs are marked, step aside, and reconnect on their own.
- Modules in the toolbar shows or hides a card on one Mac, or on every Mac at once.
- Viewers: let a client see every Mac too, for viewing only.
- Open at login for both apps, and the host can start quietly in the menu bar.
images/screenshots/mac-settings.png
Record now, look back later
History is off by default. Turn it on in Settings (⌘,), or click "History is off" at the bottom of the sidebar. Each Mac also has its own Record history switch.
- One row per Mac per interval (10 seconds by default): averages, plus the peak for CPU, GPU and network.
- Connects, disconnects and other events are recorded too.
- One SQLite file per day, kept for as many days as you choose (30 by default), with an optional size limit.
- About 16 MB a day for 10 Macs at the default interval.
images/screenshots/history-export.png
Export exactly what you need
Export… writes CSV (a samples file and an events file) or JSON, for the Macs you pick and an exact time range, even across midnight.
Quick ranges
Last Hour, Today and other presets fill in the range for you. Or set the start and end date and time yourself.
Never misses a sample
While a Mac is recorded, it samples every module at least as often as the interval, even when nothing is on screen and the dashboard's window is closed.
Ready to try it?
It's free. Download the dashboard and the client, and pair your first Mac in a few minutes.