Pimp My IDE / garage dispatch
Back to garage
October 2, 2026 | macOS / agent permissions

Full disk is not a feature toggle.

Apple says stronger Full Disk Access controls are coming as autonomous agents raise the cost of broad file access. The right migration starts before the new prompt appears.

Treat Full Disk Access as an exception. Record the exact files, process chain, revocation route, and negative test before an agent gets the key.
Storage apertureFull disk open
Requested jobSystem-wide reach

Apple called out the whole blast radius.

Apple's October 2 developer notice says Full Disk Access can expose files, mail, messages, browsing history, and communication data. Apple says some developers use it in ways that users may not understand. The company plans more controls that require explicit user action.[1]

The notice does not name an operating-system release, enforcement date, entitlement, or replacement API. It is a direction notice, not a migration specification. Do not invent a deadline or promise that today's setup will keep working unchanged.

When the requested job names one folder, a request for every file is a design failure.

The current switch reaches far past source code.

Apple's Mac User Guide says Full Disk Access includes other apps' data, Time Machine backups, and certain administrative settings for all users. The same settings page lists narrower controls for Files and Folders, Automation, Accessibility, App Management, Input Monitoring, and screen recording.[2]

Those permissions are not interchangeable. Reading a repository, driving another app, monitoring input, and changing installed software are separate capabilities. A coding agent may use several processes, so document the editor, terminal, helper, language server, and spawned tool that touches each protected resource.

Management is not silent consent.

Apple's deployment guide documents the Privacy Preferences Policy Control payload for managed Macs. It says the payload requires user approval. If several payloads apply, macOS uses the more restrictive settings. The guide also identifies apps through code-signing requirements or bundle identifiers, not through a product name alone.[3]

That gives teams a better inventory format. Record the exact binary identity, permission, reason, owner, and removal test. A policy profile can describe an allowed route. It does not prove that an agent stayed inside the project or that revocation stopped every child process.

Start with the smallest file route.

  1. Name every directory the workflow reads and writes.
  2. Map each directory to the exact process that opens it.
  3. Use selected folders or a dedicated workspace when the job permits it.
  4. Keep credentials and private communication stores outside the workspace.
  5. Remove the grant, restart the process chain, and run a negative test.

A future system prompt may make the warning harder to ignore. The useful fix is still in the application. Ask for less, explain the remainder, and keep proof that the smaller route works.

Interactive makeover / access customs bay

Set the storage aperture.

Traditional purpose replaced: one Full Disk Access checkbox. Better version: choose the smallest file scope, light the review requirements, and copy a request that keeps real evidence blank.

Access request

These controls draft a review request. They do not read macOS settings or grant a permission.

Requested file scope
Review-request sections
Generated review request

Keep the aperture honest

The aperture shows requested file reach. The clamps show selected review sections. Neither one measures current host permissions.

Storage reachProject only
Project request incomplete.No review-request section is selected.
Four selected sections mean the request structure is ready. They do not prove that access is narrow, approved, removed, or tested. Full Disk Access remains an exception even when the template is complete.

Sources read

Source log and evidence boundary
  1. Apple Developer, "Updates to Full Disk Access in macOS", published and read October 2, 2026. This is the first-party notice for Apple's stated concern, examples of exposed data, agent-risk rationale, and plan for more explicit user action. It does not publish a release date or technical migration path.
  2. Apple Mac User Guide, "Change Privacy & Security settings on Mac", read October 2, 2026. It defines current Full Disk Access reach and lists separate controls for files, automation, accessibility, app management, input, and screen recording.
  3. Apple Platform Deployment, "Privacy Preferences Policy Control device management payload settings", read October 2, 2026. It documents user approval, restrictive-policy precedence, enrollment support, and application identification fields for managed Macs.
  4. Hacker News item 49937631, resolved through the official Hacker News API on October 2, 2026. It was the discovery signal and supports none of the technical claims.

Evidence boundary. We read Apple's notice and current support documents. We did not test an unreleased macOS control, inspect a developer seed, change a Mac permission, or confirm how future enforcement will work. The customs bay is a teaching aid. It produces a review template and does not inspect or change host access.