The Windows agent supports Advanced Elevation Rules that auto-approve or auto-deny future UAC requests based on file path, file name, product name, MD5 hash, and/or publisher certificate — and those rules can be scoped to a single machine, a group, or the entire org. Once a rule exists, other users never even have to submit a request for that installer.
The macOS agent (now GA) currently only supports session-based elevation with manual technician approve/deny — there's no equivalent rule engine to auto-allow known-good installers/apps org-wide.
Request: bring file- and/or code-signing-identity-based auto-approve/deny rules to the macOS agent, matching the spirit of the Windows Advanced Elevation Rules (e.g., match on bundle ID, code signature/Team ID, notarization status, and/or path), scoped per-machine/group/org the same way.
This would close the biggest functional gap between the Windows and Mac agents and let MSPs actually reach "zero standing admin" on mixed fleets without turning Mac elevation into a 100%-manual-approval workflow.
Here's a draft ready to post on roadmap.cyberfox.com/autoelevate: