Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260831-1822-fleet-tcc-agent-privileges

rdmsm4x — fleet TCC agent privileges audit and remediation

Session: 2026-08-31 18:09 EDT → 2026-08-31 (rdmsm4x, macOS 27.0 26A5421a, arm64) Ticket: SEC-20260831-09 · Project: ~/dev/fleet/tcc-privileges · Skill: macos-permissions

Audited macOS TCC privileges (Screen Recording, Full Disk Access, Accessibility, Input Monitoring, Post Event) for every agent CLI and terminal / agent-host app across all six fleet Macs, requested the grants that have a request API, and captured the rest as an exact per-host switch list. The headline: an agent CLI is its own TCC subject, so granting the terminal app grants nothing to the agent running inside it.

Scope

All six hosts measured: rdmsm4x, rdmbair15m5, rdmbair13m5, jdmbair13m5 (reached by tailnet IP 100.86.185.90 — its MagicDNS name does not resolve from rdmsm4x), rdmpw3265m, rdmpw3275m. brmbairm1 refused SSH (Remote Login off) and was not measured.

What changed on this host

Nothing was changed on any remote host: they were read only (probe + TCC dump). /tmp/tcc_probe, /tmp/remote_audit.sh and /tmp/tcc_dump.sh were copied to each and can be deleted at any time.

The finding

Same machine, same binary, same minute:

probe in a plain Terminal.app window : full_disk_access  OK
probe under the claude CLI           : full_disk_access  MISS

com.apple.Terminal holds Full Disk Access; /opt/homebrew/Caskroom/claude-code@latest/2.1.251/claude is DENIED it. Because claude is separately signed it becomes its own TCC responsible process, and every command it spawns is attributed to it. Terminal's ticked box was never the answer to the question being asked.

Two further consequences:

Hard limits confirmed

Verification

Outstanding — needs Rich (GUI clicks, cannot be automated)

Full list with exact switches: ~/dev/fleet/tcc-privileges/GAPS.md.

  1. rdmsm4x — Full Disk Access for the claude and antigravity CLIs (both already listed, switches off). Quit and relaunch the CLI afterwards; FDA applies to new processes only.
  2. rdmpw3265m and rdmpw3275m — Terminal, Ghostty and Warp hold no Screen Recording and no Accessibility at all. Both Intel hosts.
  3. jdmbair13m5, rdmbair13m5, rdmpw3275m — sshd Accessibility is explicitly DENIED. A denied row never re-prompts; only the Settings toggle clears it.
  4. Decide the durability policy for path-pinned CLI grants (re-grant after each upgrade, vs an MDM PPPC profile keyed on the signing identity).

Undo

No secrets were read, written or logged. TCC databases were read only; none was modified.