Kavanati — deploying to a team

Last updated: 6 October 2026 · applies from version 1.12.0 · describes version 1.12.0

Two things reach each computer: the app and your organization's license key. The app is one portable file on Windows and one notarized app on Mac. The key goes in once, centrally — a registry policy, a small text file next to the exe, or an MDM profile — and every computer activates itself silently at start-up. Nobody types the key, and IT decides whether the app may update itself. No MSI yet (see what isn't ready).

1. Windows: the file

Kavanati-windows.exe is a single self-contained file (about 50 MB). It needs no installer and no admin rights, and it runs per user: the first run registers "Start with Windows" for that user (HKCU\…\Run) and adds a Start Menu shortcut. Download the current build from kavanati.com and keep it on a share or in your deployment tool.

2. The license key, without typing it anywhere

From version 1.12.0 the app looks for a managed license key at start-up. The first place that has one wins:

WhereValueUse it when
HKLM\SOFTWARE\Policies\KavanatiLicenseKey (REG_SZ) = KAV-XXXX-XXXX-XXXX-XXXXGroup Policy, Intune or RMM for the whole computer (recommended).
HKCU\SOFTWARE\Policies\Kavanatisame valueA per-user policy or a logon script without admin rights.
Kavanati.license next to the exea text file whose first line is the key; lines starting with # are commentsYou copy a folder and nothing else. Handy for RMM tools and small offices.

At start-up each computer activates itself against the license server and takes one seat (section 6). The user sees "License: KAV-… · managed by your organization" in the Plan menu, and the "Disconnect this device" item is hidden — a managed key would simply come back at the next start. If the computer is offline at logon, the app retries every few hours; "Check for updates…" in the menu forces a retry right away. When the key has no free seat left, the user gets one short message and the app keeps working on the free plan until IT adds computers to the license.

A personal Pro key that a user had entered before is replaced by the organization's key on a managed computer. Removing the policy value does not remove the license from computers that already activated; to move a seat, release the old computer from the key (write to support@kavanati.com) or let it free itself after 45 days unseen.

3. Updates: self-update or managed

By default the app downloads a new version in the background, verifies its SHA-256 against the published value and asks the user to restart. If you deploy software centrally, turn that off:

4. Sample: one script for a logon task, Intune or RMM

User context, no admin rights. Adjust the share path and the key. The copy runs only when the file is missing, so a self-updated newer build is not overwritten; when you turn self-update off, copy unconditionally on each new release.

# Kavanati rollout (per user) — PowerShell 5.1+
$key = "KAV-XXXX-XXXX-XXXX-XXXX"
$dir = Join-Path $env:LOCALAPPDATA "Kavanati"
$exe = Join-Path $dir "Kavanati.exe"
New-Item -ItemType Directory -Force $dir | Out-Null
if (-not (Test-Path $exe)) { Copy-Item "\\server\software\Kavanati-windows.exe" $exe -Force }
$pol = "HKCU:\SOFTWARE\Policies\Kavanati"
New-Item -Path $pol -Force | Out-Null
Set-ItemProperty -Path $pol -Name LicenseKey -Value $key
# Set-ItemProperty -Path $pol -Name SelfUpdate -Value 0 -Type DWord   # only if IT ships updates
if (-not (Get-Process Kavanati -ErrorAction SilentlyContinue)) { Start-Process $exe }

With Group Policy Preferences, create the two registry values under HKLM\SOFTWARE\Policies\Kavanati instead of the HKCU lines, and use a user logon script just to copy and start the exe. An ADMX template is on the list (section 8).

5. Mac

Kavanati-mac.zip contains Kavanati.app, Developer-ID signed and notarized by Apple. Place it in /Applications with your MDM or a script. Each user must approve Accessibility and Input Monitoring once; the app opens the right System Settings pane and starts working the moment they are granted. Accessibility can be pre-approved through a PPPC profile. Apple does not let MDM pre-approve Input Monitoring, so the user clicks that one.

The license key and the update switch are read from the app's preferences domain, com.melogix.langguard (the app's original internal name, kept for compatibility):

WhereKeysUse it when
A configuration profile (Jamf, Intune, Kandji, Mosyle…), payload type com.melogix.langguard LicenseKey (string), SelfUpdate (boolean)Managed Macs. Wins over everything below.
sudo defaults write /Library/Preferences/com.melogix.langguard LicenseKey "KAV-…" same keysA script for all users on the Mac.
defaults write com.melogix.langguard LicenseKey "KAV-…"same keys One user, no admin rights.
/Library/Application Support/Kavanati/Kavanati.licensea text file whose first line is the keyTools that push files rather than preferences.

Minimal profile payload (inside a standard .mobileconfig):

<dict>
  <key>PayloadType</key><string>com.melogix.langguard</string>
  <key>PayloadIdentifier</key><string>com.example.kavanati.license</string>
  <key>PayloadUUID</key><string>6F0C4A2E-1B2D-4C3E-9F8A-7E6D5C4B3A21</string>
  <key>PayloadVersion</key><integer>1</integer>
  <key>LicenseKey</key><string>KAV-XXXX-XXXX-XXXX-XXXX</string>
  <key>SelfUpdate</key><false/>
</dict>

Everything in section 2 about silent activation, retries, the managed label and seats applies to Macs the same way. The app adds itself as a login item on the first run.

6. Seats: how computers are counted

7. Measuring a pilot

The app keeps a counter on each computer, never sent anywhere: the menu header reads "Corrections: 1,284 · This month: 212". For a 30-day pilot, ask the participants for that line (or a screenshot of the menu) on day 21 or 30. Request a pilot key on the teams page; it covers up to the number of computers you name, for 30 days, and simply expires.

8. What isn't ready yet

Questions from IT, procurement or security: support@kavanati.com. See also the security & IT overview and Kavanati for teams.

← Kavanati for teams