Configuration editor info Values set here apply at the selected scope. Enforce locks a value for everything below (most-general wins); a plain value is a default the more specific scope may override. Every change passes the gate and commits to git. Changing a value here configures it. If it is something your organisation has to be able to DEMONSTRATE - and most controls are - set it through a policy instead: that records why, keeps a lower scope from weakening it, and re-checks it. See Policies.
You are editing
appsCapabilities info One click turns on a capability and its sensible companions, leaving only the real choices visible. Applies at the scope above; adjust anything afterwards.
shield_personSecure workplace
Harden a staff laptop in one step: Secure Boot on, the office suite installed, and a conservative SSH login limit. Apply it, then adjust anything below.
inventory_2Apps at this scope info Additive across the chain: a device gets the union of org, group ancestry and its own lists. Names only (nixpkgs attrs, flathub ids, repo overlays) - never code.
packages
nothing at this scope
flatpaks
nothing at this scope
overlays
nothing at this scope
Edit list · packages
One name per line, or comma-separated.
Edit list · flatpaks
One name per line, or comma-separated.
Edit list · overlays
One name per line, or comma-separated.