Libretto Work: restricting speech output

Guide for administrators. General information and licensing: Libretto Work.

What is this about?

Libretto reads answers aloud. By default the iOS system voice speaks locally on the device, so no text leaves the device. Users can optionally enable a cloud voice (OpenRouter, with their own key). Answer texts then go to that service. As an organization you can define which speech output is allowed.

Important: Employees cannot loosen a policy of the organization. Local settings or rules in the app can only restrict it further. What all sources (device management, server, local rule) allow is permitted. The system voice is always allowed.

Two ways, which can be combined:

Way A: Managed app configuration (MDM)

For organizations with device management (Microsoft Intune, Jamf, Workspace ONE and others). The configuration applies to the whole app on the managed device, employees cannot change it, and changes arrive live in the app. App bundle ID: net.keutgen.libretto.

KeyTypeMeaning
speechAllowedEnginesArray of stringsAllowed speech output for all profiles. Values: system, openrouter
speechRulesArray of objectsAllowed speech output per domain: host (domain, subdomains count) and allowedEngines

Example 1: only the local system voice, on the whole device.

<dict>
  <key>speechAllowedEngines</key>
  <array>
    <string>system</string>
  </array>
</dict>

Example 2: only your domain gets the system voice, employees’ private profiles stay unaffected.

<dict>
  <key>speechRules</key>
  <array>
    <dict>
      <key>host</key>
      <string>firma.de</string>
      <key>allowedEngines</key>
      <array>
        <string>system</string>
      </array>
    </dict>
  </array>
</dict>

In Microsoft Intune: Apps → iOS/iPadOS → App configuration policies → Add → Managed devices, select the Libretto app and choose “Enter XML data” as the format. Enter the <dict> from one of the examples. In Jamf you enter the same under the app’s App Configuration.

Way B: File on your LibreChat server

For organizations without device management. Your server delivers a small JSON file at

https://<your-server>/.well-known/libretto.json
{
  "version": 1,
  "speech": { "allowedEngines": ["system"] }
}
  • Libretto fetches the file when a profile loads and when the app returns to the foreground, and remembers the policy per server.
  • Offline the last known policy applies.
  • If you remove the file, the policy ends at the next fetch. If the server returns the chat page (HTML) or 404, that counts as “no policy”.
  • The file must be reachable without sign-in.

nginx:

location = /.well-known/libretto.json {
    default_type application/json;
    add_header Cache-Control "no-store";
    return 200 '{"version":1,"speech":{"allowedEngines":["system"]}}';
}

Apache:

Alias /.well-known/libretto.json /var/www/libretto.json
<Files "libretto.json">
    ForceType application/json
</Files>

How to check the effect

  1. Install Libretto on a test device and create a profile for your instance.
  2. Open … → Voice mode. With way A the section “From your organization” appears at the top with your policies, and blocked engines are missing from the selection.
  3. In the profile, under “Voice mode”, try choosing OpenRouter. Below the selection a note says that a policy blocks the choice.
  4. Start a conversation. The profile’s debug log names the source, for example (the log is written in German): “Sprachausgabe: iOS-Systemstimme (Richtlinie des Servers für … sperrt OpenRouter)”.

Limits

  • The server file applies to the profile with that address. If an employee enters the same server under another address (IP address, own proxy), the app does not receive the file. A policy through MDM (per domain or for all profiles) cannot be bypassed this way. A list of allowed servers in the MDM configuration is planned.
  • The policy protects the app’s speech output. Text can still be copied and read aloud elsewhere. It is protection against unintentional leakage, not complete data security.
  • Speech recognition (speech to text) runs on the device by default. There is currently no central policy for it.

Contact

Technical questions: support@computeq.de
Licenses and quotes: sales@computeq.de

As of: 7 October 2026