rdmsm4x — fleet TCC agent privileges audit and remediation
Session: 2026-08-31 18:09 EDT → 2026-08-31 (rdmsm4x,
macOS 27.0 26A5421a, arm64) Ticket: SEC-20260831-09 ·
Project: ~/dev/fleet/tcc-privileges ·
Skill: macos-permissions
Audited macOS TCC privileges (Screen Recording, Full Disk Access, Accessibility, Input Monitoring, Post Event) for every agent CLI and terminal / agent-host app across all six fleet Macs, requested the grants that have a request API, and captured the rest as an exact per-host switch list. The headline: an agent CLI is its own TCC subject, so granting the terminal app grants nothing to the agent running inside it.
Scope
All six hosts measured: rdmsm4x, rdmbair15m5, rdmbair13m5,
jdmbair13m5 (reached by tailnet IP 100.86.185.90 — its MagicDNS name
does not resolve from rdmsm4x), rdmpw3265m, rdmpw3275m.
brmbairm1 refused SSH (Remote Login off) and was not
measured.
What changed on this host
- Screen Recording granted to the
claudeCLI (/opt/homebrew/Caskroom/claude-code@latest/2.1.251/claude) — prompt fired byCGRequestScreenCaptureAccess(), approved, verified by re-probe. - Accessibility rows refreshed for the
claudeandantigravityCLIs (already allowed). - Full Disk Access placeholder rows created for the
claudeandantigravityCLIs by attempting a protected read. This is what makes them appear in System Settings › Privacy & Security › Full Disk Access with the switch off. Still off — one click each, outstanding for Rich. - New project
~/dev/fleet/tcc-privileges/(probe, dump, audit, request tooling, evidence). - New global skill
~/.claude/skills/macos-permissions/(SKILL.md +references/macOSpermissions.md+ scripts). - Ticket SEC-20260831-09 opened.
Nothing was changed on any remote host: they were read only (probe +
TCC dump). /tmp/tcc_probe,
/tmp/remote_audit.sh and /tmp/tcc_dump.sh were
copied to each and can be deleted at any time.
The finding
Same machine, same binary, same minute:
probe in a plain Terminal.app window : full_disk_access OK
probe under the claude CLI : full_disk_access MISS
com.apple.Terminal holds Full Disk Access;
/opt/homebrew/Caskroom/claude-code@latest/2.1.251/claude is
DENIED it. Because claude is separately
signed it becomes its own TCC responsible process, and every command it
spawns is attributed to it. Terminal's ticked box was never the answer
to the question being asked.
Two further consequences:
- Path pinning. Non-bundle executables are keyed by
absolute path, so every
brew upgradeof an agent CLI silently orphans its grants. rdmpw3275m carries eleven orphaned/usr/local/Cellar/uv/<version>/bin/uvrows. - Interpreters lie. The same probe run through a
framework
Python.app(Homebrew's and Xcode's both) reported Accessibility and Input Monitoring missing while a plain compiled binary in the same shell reported them granted — Python.app carries its own TCC identity.tcc_probe.pyis retained in the project purely as the counter-example.
Hard limits confirmed
/Library/Application Support/com.apple.TCC/TCC.dbis not writable even by root with SIP enabled (test -was root: not writable). No TCC grant can be scripted.- Full Disk Access has no request API at all. Screen Recording, Accessibility and Input Monitoring do, and those prompts were fired.
- MDM is enrolled and user-approved
(
axm-adm-mdm.apple.com) but carries no PPPC payload. A PPPC profile is the only way to grant these without hand-clicking. - All six hosts already grant Full Disk Access to
sshd(/usr/libexec/sshd-keygen-wrapper), sossh <host>— including to localhost — is the working privileged read path, and is how the grant tables were read at all. - An SSH session can never display a TCC prompt. Every privilege a remote job needs must exist before the job runs.
Verification
tcc_probebuilt universal:lipo -archs→x86_64 arm64(gate enforced in the build line).- Every host's posture measured functionally, not inferred from a TCC row.
- The responsible-process claim verified in both
directions with a control run
(
results/control-terminal-direct-rdmsm4x.txt). - Screen Recording grant confirmed by re-running the probe in the same context after approval.
Outstanding — needs Rich (GUI clicks, cannot be automated)
Full list with exact switches:
~/dev/fleet/tcc-privileges/GAPS.md.
- rdmsm4x — Full Disk Access for the
claudeandantigravityCLIs (both already listed, switches off). Quit and relaunch the CLI afterwards; FDA applies to new processes only. - rdmpw3265m and rdmpw3275m — Terminal, Ghostty and Warp hold no Screen Recording and no Accessibility at all. Both Intel hosts.
- jdmbair13m5, rdmbair13m5, rdmpw3275m —
sshdAccessibility is explicitly DENIED. A denied row never re-prompts; only the Settings toggle clears it. - Decide the durability policy for path-pinned CLI grants (re-grant after each upgrade, vs an MDM PPPC profile keyed on the signing identity).
Undo
- Revoke anything granted: System Settings › Privacy & Security ›
the relevant pane, or
tccutil reset ScreenCapture/tccutil reset Accessibility(resets only; it cannot grant). - Remove the project:
mv ~/dev/fleet/tcc-privileges ~/dev/archive/tcc-privileges-20260831/. - Remove the skill:
mv ~/.claude/skills/macos-permissions ~/dev/archive/. - Remote hosts:
rm /tmp/tcc_probe /tmp/remote_audit.sh /tmp/tcc_dump.sh.
No secrets were read, written or logged. TCC databases were read only; none was modified.