Decommission a device

Take macOS and Windows devices out of your Merge Workforce deployment

Use this page when devices should no longer run the Merge Workforce desktop client: a few pilot testers who want out, devices leaving your managed fleet, or the end of a deployment across your organization. It is a two-part change: take the devices out of your MDM’s scope, then clear the client from them.

For IT administrators only

Removing the client needs administrator rights on the device and access to your MDM. Employees cannot do this themselves: even with local admin rights, your MDM reinstalls required software at its next check-in, and the device goes quiet in Devices until it does. Employees with a reason to remove the client should contact IT.

Use your MDM, not the device

Taking a device out of your MDM’s scope only stops the MDM from reinstalling the client. It does not remove what is already installed. Run the uninstall through your MDM as well: it already has the administrator rights the uninstall needs, nobody has to sign in to the device, and the same steps work for one device or every device. Commands to run on a single device are at the end of each tab, for when your MDM cannot run them for you.

Pick the target first: the devices you want to decommission, or every device for an organization-wide removal. Use that same target in each step.

  1. Unassign the package. Remove the target from the Merge Workforce package assignment, so the MDM stops reinstalling the client.
  2. Run the uninstall script. Add the script below to your MDM as a script that runs as root, and run it on the target. In Jamf Pro this is a policy with a script payload, in Iru a custom script, and in Mosyle a custom command.
  3. Check the result. Each device’s script output ends with Merge Workforce desktop client removed. If anything was left behind, the output lists it and the run reports a failure, so you can rerun it on only those devices.
  4. Remove the configuration profile. Unassign the Merge configuration profile from the target. This also removes the com.merge.workforceclient managed preferences, so do not delete them by hand.
merge-workforce-uninstall.sh
#!/bin/bash
# Merge Workforce desktop client: macOS uninstall script for MDM deployment.
# Runs as root. Safe to run more than once. Exits 1 if anything is left behind.
# Unassign the Merge Workforce package in your MDM first, or it will reinstall.
set -u
KEEP_STATE=false # true keeps enrollment state, logs, and device id for a later reinstall
DAEMON_LABEL="com.merge.workforceclient.daemon"
TRAY_LABEL="com.merge.workforceclient.tray"
if [ "$(id -u)" -ne 0 ]; then
echo "Must run as root"
exit 1
fi
echo "Stopping background service"
launchctl bootout "system/${DAEMON_LABEL}" 2>/dev/null || true
for _ in $(seq 1 100); do
launchctl print "system/${DAEMON_LABEL}" >/dev/null 2>&1 || break
sleep 0.1
done
echo "Stopping menu bar app"
for uid in $(ps -axo uid=,comm= | awk '/merge-workforce-tray/ {print $1}' | sort -u); do
launchctl bootout "gui/${uid}/${TRAY_LABEL}" 2>/dev/null || true
done
pkill -x merge-workforce-tray 2>/dev/null || true
echo "Removing app and launch items"
rm -f "/Library/LaunchDaemons/${DAEMON_LABEL}.plist"
rm -f "/Library/PrivilegedHelperTools/${DAEMON_LABEL}"
rm -f "/Library/LaunchAgents/${TRAY_LABEL}.plist"
rm -rf /Applications/Merge.app
if [ -L /usr/local/bin/merge-workforce-client ]; then
rm -f /usr/local/bin/merge-workforce-client
fi
pkgutil --forget com.merge.workforceclient >/dev/null 2>&1 || true
if [ "$KEEP_STATE" != "true" ]; then
echo "Removing local data"
rm -rf "/Library/Application Support/Merge"
rm -rf /Library/Logs/Merge
while security delete-generic-password -s com.merge.workforceclient /Library/Keychains/System.keychain >/dev/null 2>&1; do :; done
fi
echo "Verifying"
leftover=0
if pgrep -x merge-workforce-tray >/dev/null || launchctl print "system/${DAEMON_LABEL}" >/dev/null 2>&1; then
echo "Still running"
leftover=1
fi
for p in "/Library/LaunchDaemons/${DAEMON_LABEL}.plist" "/Library/PrivilegedHelperTools/${DAEMON_LABEL}" \
"/Library/LaunchAgents/${TRAY_LABEL}.plist" /Applications/Merge.app; do
if [ -e "$p" ]; then
echo "Still present: $p"
leftover=1
fi
done
if [ "$leftover" -eq 0 ]; then
echo "Merge Workforce desktop client removed"
exit 0
fi
exit 1

The script stops the background service before the menu bar app, because the service starts the app. It is safe to run more than once: anything already gone is skipped.

KEEP_STATE=false also clears the client’s enrollment state, logs, and stored device id. Set it to true if you plan to reinstall on the same devices and want them to return with their previous enrollment.

On a single device without your MDM

Use this when your MDM cannot run scripts, or for a one-off test machine. Take the device out of the package and profile assignments first, then run these in Terminal as an administrator:

sudo launchctl bootout system/com.merge.workforceclient.daemon
sudo pkill -x merge-workforce-tray
sudo rm -f /Library/LaunchDaemons/com.merge.workforceclient.daemon.plist
sudo rm -f /Library/PrivilegedHelperTools/com.merge.workforceclient.daemon
sudo rm -f /Library/LaunchAgents/com.merge.workforceclient.tray.plist
sudo rm -rf /Applications/Merge.app

To also clear local data, the same as KEEP_STATE=false:

sudo rm -rf "/Library/Application Support/Merge"
sudo rm -rf /Library/Logs/Merge
sudo rm -f /usr/local/bin/merge-workforce-client
sudo security delete-generic-password -s com.merge.workforceclient /Library/Keychains/System.keychain
sudo pkgutil --forget com.merge.workforceclient

To confirm it is gone, pgrep -fl merge-workforce-tray and ls /Applications/Merge.app should both return nothing, and the Merge icon is gone from the menu bar.

What happens in Merge

Removing the client does not change your organization’s settings, Groups, or connected tools. Each device stays in Devices: it stops heartbeating, and after 30 minutes it shows as not reporting, with the time it went quiet.

To put the client back, return the devices to your MDM assignment, or see Reset a device.

Next steps