How it works

One Mac shows the dashboard. Every other Mac runs a small client that reports to it, over an encrypted connection that only paired Macs can open.

The two apps

A dashboard, and a client on each Mac

SystemStatusRemote, the host

Runs on the Mac you look at. Shows the dashboard, lists the Macs being watched, accepts pairing requests and stores history. It lives in the menu bar too, so it keeps listening and recording with its window closed.

SystemStatusClient, the client

Runs on each Mac you want to watch, as a menu-bar item with no window. It connects out to the host, samples what the host asks for, and reports once per interval.

How the apps connect Three client Macs each open an encrypted connection to the host Mac on port 47820. The host shows the dashboard and can record history to a database. MacBook Air SystemStatusClient Mac mini SystemStatusClient iMac SystemStatusClient TLS 1.3 · mutual auth · :47820 Mac Studio SystemStatusRemote History (optional)

Clients dial out to the host, so only the host needs to accept incoming connections.

Set up

From download to dashboard

You need macOS 15 (Sequoia) or later on every Mac, and the Macs must reach each other over the network. Download both apps first.

Open the host

Open SystemStatusRemote on the Mac that will show the dashboard. When macOS asks to accept incoming connections, choose Allow. The bottom of the sidebar should say "Listening on port 47,820".

Add Client… shows the name clients will see it under, and its address, and starts taking pairing requests (for 15 minutes, or the time chosen in Settings).

Open the client and request pairing

Open SystemStatusClient on the Mac you want to watch, then click its menu-bar item. Hosts on the same network are listed under Host by their Mac's name. For a host on another network, choose Enter an Address and type its address and port 47820.

Click Request Pairing. The client shows a check phrase of three words and waits.

Accept on the host

Whenever it suits you, find the request under Pairing Requests at the top of the host's sidebar (the menu-bar item shows a count). Click Accept…, check that the host shows the same three words, and accept.

The client then shows the words again: click Yes, Pair if they're the ones the host showed. It connects, and the Mac appears in the sidebar with a green dot.

First launch prompts. Each app keeps its identity key in the Keychain, so macOS asks once: choose Always Allow. A client may also ask to find devices on your local network: choose Allow (or turn it on later in System Settings › Privacy & Security › Local Network).

Pairing

Three words that prove it's really your Mac

When a client asks to pair, both Macs show the same check phrase, made from both Macs' certificates:

maple · river · copper

If the words match, accept on the host and confirm on the client. If they differ, deny the request: something else on the network may be posing as one of the Macs. A denied client is turned away for 15 minutes.

A machine in the middle sees different certificates on each side, so the two Macs would show different words. Its chance of faking a match is one in 16.7 million per attempt, and the host and the client each stop a request that keeps starting over, so it gets very few attempts.

  • No rush: a request waits as long as the client keeps asking, up to a day.
  • Prefer a code? Pair with a code instead gives a one-time code to type on the client.
  • Choose in the host's Settings how long it takes requests: Off, 15 minutes, 1, 4 or 8 hours, or Always.
The host's Accept sheet showing the check phrase
Screenshot: accepting a pairing request The host's Accept sheet with the three words images/screenshots/pairing-accept.png
On the host: check the words, then accept.
Security

Private by design

Your Macs talk only to each other. There's no account to make and no service in the middle.

Encrypted both ways

Every connection uses TLS 1.3 with mutual authentication: the client checks the host, and the host checks the client. Nothing is accepted before both sides are authenticated, and every message is size-limited and validated.

Pinned after pairing

Pairing pins each side's certificate, so afterwards only the paired Macs can connect. Each app keeps its identity key in the Keychain. Remove a client on the host and it can't connect again until paired anew.

Found isn't trusted

Seeing a host on the network doesn't make it trusted; accepting the request and comparing the words does. Once paired, a client recognizes its host by certificate, so it keeps connecting even if the host's address or name changes.

Sandboxed and notarized

Both apps run in the macOS App Sandbox with only the entitlements they need, and every release is signed with a Developer ID and notarized by Apple. History stays inside the app's container, protected by FileVault.

The dashboard

Built for watching many Macs

  • Overview shows several Macs side by side. Click one for a full-size view.
  • Order: drag Macs up and down the sidebar. The Overview follows.
  • Compare Macs: Command- or Shift-click Macs, then choose By Mac or By Module.
  • The gear on a Mac's panel sets its modules, how often it samples, and whether it's in the Overview.
  • Not responding, then Offline: quiet Macs are marked, step aside, and reconnect on their own.
  • Modules in the toolbar shows or hides a card on one Mac, or on every Mac at once.
  • Viewers: let a client see every Mac too, for viewing only.
  • Open at login for both apps, and the host can start quietly in the menu bar.
A Mac's settings sheet: modules, sample interval and history
Screenshot: a Mac's settings The gear sheet: modules, sample interval, Record history images/screenshots/mac-settings.png
History

Record now, look back later

History is off by default. Turn it on in Settings (⌘,), or click "History is off" at the bottom of the sidebar. Each Mac also has its own Record history switch.

  • One row per Mac per interval (10 seconds by default): averages, plus the peak for CPU, GPU and network.
  • Connects, disconnects and other events are recorded too.
  • One SQLite file per day, kept for as many days as you choose (30 by default), with an optional size limit.
  • About 16 MB a day for 10 Macs at the default interval.
The history Export sheet
Screenshot: exporting history The Export sheet: Macs, time range, CSV or JSON images/screenshots/history-export.png

Export exactly what you need

Export… writes CSV (a samples file and an events file) or JSON, for the Macs you pick and an exact time range, even across midnight.

Quick ranges

Last Hour, Today and other presets fill in the range for you. Or set the start and end date and time yourself.

Never misses a sample

While a Mac is recorded, it samples every module at least as often as the interval, even when nothing is on screen and the dashboard's window is closed.

Ready to try it?

It's free. Download the dashboard and the client, and pair your first Mac in a few minutes.