Feature Comparison

Built by the team that maintains Santa, Workshop has deep integrations because we control both ends of the system.

New Santa features are supported in Workshop first, every time.

Feature comparison of Santa Lite and Santa & Workshop Enterprise
FeatureSantaLiteSanta & WorkshopEnterprise
Binary Authorization
Monitor Mode
Log all executions without blocking
AvailableAvailable
Lockdown Mode
Block all executions not explicitly allowed
AvailableAvailable
Standalone Mode
Operate without any sync server
AvailableAvailable
Allow/Block Rules
Rules by SHA-256, Signing ID, Certificate, CDHash, or Team ID
AvailableAvailable
Bundle Rules
Allow or block entire application bundles. Depends on sync server support, which is rare.
PartialAvailable
Transitive / Compiler Rules
Auto-allow binaries created by trusted compilers
AvailableAvailable
CEL Policy Engine
CEL Rule Support
Common Expression Language policy evaluation
AvailableAvailable
CEL Access to euid & cwd
Effective user ID and current working directory in rules
AvailableAvailable
TouchID Requirement via CEL
Require biometric authentication for execution
UnavailableAvailable
Process Tree CEL Evaluation
CEL rules that evaluate full process tree context
UnavailableAvailable
File Access Authorization
FAA Policy Support
Control access to protected file paths
AvailableAvailable
Glob Path Support
Glob patterns for Data and Proc FAA rules
AvailableAvailable
FAA Log Rate Limiting
Configurable rate limiting for FAA events
AvailableAvailable
FAA Rules via Sync
Manage FAA rules centrally through the sync protocol
UnavailableAvailable
FAA Block Event Upload
FAA block events uploaded and visible in the console
UnavailableAvailable
Removable Media & Network
USB / SD Card Blocking
Block removable media mounting
AvailableAvailable
Remount with Flags
Remount removable media with restricted flags
AvailableAvailable
Network Share / Mount Blocking
Block network mounts with configurable exception lists
UnavailableAvailable
Network Telemetry
Network event reporting and visibility
UnavailableAvailable
Removable Media Event Upload
USB/SD events uploaded and visible in the console
UnavailableAvailable
Approval Workflows
Self-Service Approval
Empower trusted users to approve their own low-risk software
UnavailableAvailable
Designated Approvers
Route requests to managers, specific users, or tag-based groups
UnavailableAvailable
Multi-Approver Thresholds
Require multiple approvers for added oversight
UnavailableAvailable
Social Voting
Community-driven approval with local and global vote thresholds
UnavailableAvailable
Slack Bot Integration
Complete approval workflows directly in Slack
UnavailableAvailable
On-Demand Monitor Mode
Temporary Lockdown bypass with admin-configured max duration and auto-revert
UnavailableAvailable
Risk Engine
VirusTotal Integration
Automatic SHA-256 lookup against VirusTotal with caching
UnavailableAvailable
ReversingLabs Integration
Automatic lookup against ReversingLabs Spectra Intelligence
UnavailableAvailable
Blockable Rules Plugin
CEL expressions to flag entire classes of software
UnavailableAvailable
Custom Risk Plugins
Write your own HTTP-based risk engine plugins
UnavailableAvailable
Risk Engine Exceptions
Override plugin decisions per tag with expiration dates
UnavailableAvailable
Flag Blockables as Malicious
Halt all approval workflows for flagged binaries
UnavailableAvailable
Telemetry & Event Export
Protobuf Telemetry Logging
Structured telemetry with gzip compression
AvailableAvailable
Unified Logging Integration
macOS Unified Logging System support
AvailableAvailable
Cloud Event Export
Export execution, FAA, USB, and audit events to AWS S3 or GCP GCS
UnavailableAvailable
Telemetry Upload
Upload telemetry data to your sync server
UnavailableAvailable
Telemetry Querying
Search and query telemetry data from the console
UnavailableAvailable
Telemetry Filtering Expressions
Redact or filter telemetry before export
UnavailableAvailable
Event Analytics
Event trend data and approval workflow metrics
UnavailableAvailable
Remote Management
Remote Process Termination
Kill arbitrary processes on managed hosts remotely
UnavailableAvailable
Push Sync Trigger
Force an immediate sync from the server
UnavailableAvailable
Agent Ping
Check agent connectivity in real time
UnavailableAvailable
Administration Console
Web Dashboard
Manage hosts, rules, events, and blockables in a browser
UnavailableAvailable
Tag-Based Policy System
Flexible tag assignment with deterministic ordering
UnavailableAvailable
Reports & Analytics
Top blockables, dangerous entitlements, and lockdown readiness reports
UnavailableAvailable
Comprehensive Audit Log
Every UI and API change recorded with diffs
UnavailableAvailable
Full API Coverage
gRPC/Connect API for all Workshop operations
UnavailableAvailable
MCP Server
Model Context Protocol server for LLM integrations
UnavailableAvailable
AI Chat
Natural language queries against Workshop data
UnavailableAvailable
Identity & Access
SSO Authentication
Identity provider login for the admin console
UnavailableAvailable
Directory Sync (SCIM)
Automatic user and group sync from your IdP
UnavailableAvailable
Role-Based Access Control
Granular permissions with assignable roles
UnavailableAvailable
Multi-Party Approval
Require multiple admins for destructive actions like disabling MPA or creating API keys
UnavailableAvailable
UI & Localization
Block Notification Dialogs
Configurable messages with clickable links
AvailableAvailable
Co-Branding
Custom company name and logo on Santa UI dialogs
AvailableAvailable
Santa Menu Bar Item
Trigger sync and reset silenced notifications from the menu bar
AvailableAvailable
Security & Platform
Anti-Tamper Protections
Tamper protection for rules, events databases, and sync state
AvailableAvailable
macOS 14+ Support
Validated through macOS Tahoe 26.0
AvailableAvailable
Automatic Workshop Updates
Configurable update modes with maintenance windows
UnavailableAvailable

Ready to upgrade to Workshop?

Get enterprise-grade allowlisting with approval workflows, risk engine integrations, and a full management console.

Contact Us