Apple called out the whole blast radius.
Apple's October 2 developer notice says Full Disk Access can expose files, mail, messages, browsing history, and communication data. Apple says some developers use it in ways that users may not understand. The company plans more controls that require explicit user action.[1]
The notice does not name an operating-system release, enforcement date, entitlement, or replacement API. It is a direction notice, not a migration specification. Do not invent a deadline or promise that today's setup will keep working unchanged.
When the requested job names one folder, a request for every file is a design failure.
The current switch reaches far past source code.
Apple's Mac User Guide says Full Disk Access includes other apps' data, Time Machine backups, and certain administrative settings for all users. The same settings page lists narrower controls for Files and Folders, Automation, Accessibility, App Management, Input Monitoring, and screen recording.[2]
Those permissions are not interchangeable. Reading a repository, driving another app, monitoring input, and changing installed software are separate capabilities. A coding agent may use several processes, so document the editor, terminal, helper, language server, and spawned tool that touches each protected resource.
Management is not silent consent.
Apple's deployment guide documents the Privacy Preferences Policy Control payload for managed Macs. It says the payload requires user approval. If several payloads apply, macOS uses the more restrictive settings. The guide also identifies apps through code-signing requirements or bundle identifiers, not through a product name alone.[3]
That gives teams a better inventory format. Record the exact binary identity, permission, reason, owner, and removal test. A policy profile can describe an allowed route. It does not prove that an agent stayed inside the project or that revocation stopped every child process.
Start with the smallest file route.
- Name every directory the workflow reads and writes.
- Map each directory to the exact process that opens it.
- Use selected folders or a dedicated workspace when the job permits it.
- Keep credentials and private communication stores outside the workspace.
- Remove the grant, restart the process chain, and run a negative test.
A future system prompt may make the warning harder to ignore. The useful fix is still in the application. Ask for less, explain the remainder, and keep proof that the smaller route works.