EDIT: Removing the usual rant, worked with a Wacom dev team contact,
verified these settings work with Monterey on Intel and M1:Codesign
commands, to gather the info needed for the PPPC configuration profile:$
codesign -dr - /Applications/Wacom\ Tabl...
FWIW we've been advised by Apple to use the MDM method of enabling users
to run Software Updates through the prefs pane. Seems to be more
reliable than the old school method of building policies to do it.
@markanderson wrote:So the best solution is :1. Create the restricted
shell. ...2. Modify the target user for the shell as restricted shell.3.
Create a directory under /home/localuser/ , e.g. programs. ...Now if you
check, the user localuser can acce...