Lesson 2 of 4 · 8 min
Permissions and sandboxing on macOS
How the app sandbox, the privacy permission prompts, and your account type each limit what software can do.
An operating system that only separated processes from each other would still leave a gap: an app could still ask for your camera, your contacts or your entire disk, and get it silently. macOS closes that gap with three overlapping ideas: the app sandbox, a privacy permission system, and the type of account you are logged in as.
The app sandbox: isolating apps from each other
Apple’s platform security documentation states that ‘all apps from the App Store are sandboxed to restrict access to data stored by other apps. If an app from the App Store needs to access data from another app, it can do so only by using the APIs and services provided by macOS.’ In practice, a sandboxed app cannot simply reach into another app’s folder or memory; it has to go through a channel macOS controls, which is what makes the next layer, permission prompts, meaningful rather than easy to bypass.
The privacy permission prompts you see every day
Apple describes the principle behind the prompts you see plainly: ‘Apple believes that users should have full transparency, consent, and control over what apps are doing with their data.’ On current macOS, this is enforced by the system itself, so an app cannot quietly read your files in Documents, Downloads, Desktop, iCloud Drive or a network volume without your consent first.
System Settings > Privacy & Security lists the categories apps can ask to use, including Camera, Microphone, Location Services, Contacts, Photos, Full Disk Access, Screen & System Audio Recording, and Accessibility, each with a short description of what allowing it lets an app do. Two are worth knowing by name: Full Disk Access, which ‘allows apps to access all files on your computer, including data from other apps’, and Accessibility, which lets an app ‘run scripts and system commands to control your Mac’. Both are far broader than most apps need, so a request for either deserves a second look.
- A first request always shows a prompt naming the app and the permission, before any access is granted.
- You can review and revoke any permission later in System Settings > Privacy & Security, without uninstalling the app.
- Full Disk Access and Accessibility must be turned on manually in Settings; macOS will not grant them from a simple pop-up.
Standard vs administrator: the account you log in as
The third layer is your account type. Apple’s Mac User Guide explains that an administrator ‘can add and manage other users, install apps, and change settings’, and warns: ‘Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.’ A standard account, by contrast, ‘can install apps and change their own settings, but can’t add other users or change other users’ settings.’ Using a standard account for daily work, and reserving the administrator account for the moments that need it, keeps a mistake or a tricked click from reaching system-wide settings.
Key takeaways
- The app sandbox stops one app from reaching another app’s data directly; access has to go through macOS itself.
- macOS is built to give users, in Apple’s words, ‘transparency, consent, and control’ over what apps do with their data.
- Full Disk Access and Accessibility are unusually broad permissions and must be turned on manually in Settings.
- You can review or revoke any app’s permissions at any time in System Settings > Privacy & Security.
- An administrator account can change any setting and manage other users; a standard account cannot, which is why daily use should happen on a standard account.
Check yourself
1. What does the app sandbox prevent, according to Apple’s documentation?
- An app from starting up automatically
- An app from reaching another app’s data except through macOS-provided services — Right.
- An app from ever using the internet
- An app from being updated
Sandboxed apps can only access another app’s data through the APIs and services macOS provides, not directly.
2. Which of these permissions must be turned on manually in System Settings, rather than granted from a simple pop-up?
- Full Disk Access — Right.
- Nothing; every permission uses the same pop-up
- Wi-Fi access
- Opening the App Store
Full Disk Access (and Accessibility) require a manual change in Privacy & Security settings, since they are unusually broad.
3. Why does Apple recommend against automatic login for an administrator account?
- It slows down startup
- It uses more battery
- Anyone who restarts the Mac could gain administrator access without a password — Right.
- It disables Time Machine
With automatic login enabled for an administrator, a simple restart hands anyone administrator privileges without entering a password.
4. What can a standard account do on its own, without an administrator?
- Add a new user to the Mac
- Install apps and change its own settings — Right.
- Change another user’s password
- Turn off FileVault for the whole Mac
Standard accounts can install apps and adjust their own settings, but cannot manage other users or Mac-wide settings.
Do it with FireAI
Put this lesson into practice on your own Mac.
- Answer your first connection prompt, and what each lifetime means — Understand exactly what you’re approving the first time FireAI asks.
- Find apps with known security flaws — Close known holes before anyone uses them: update the one app that needs it.
- See which app turns on your camera or microphone, and where its traffic goes — Know which app can see or hear you, not just that something can.
Sources
- Apple Platform Security: Gatekeeper and runtime protection in macOS
- Apple Platform Security: Controlling app access to files in macOS
- Apple Support: Change Privacy & Security settings on Mac
- Apple Support: Add a user or group on Mac
Put it into practice on your Mac
Try every feature free for 17 days, no card needed.