Which macOS permissions does an AI assistant need?

Grux OS declares nine macOS permissions, and only five of them are required by any feature at all. An assistant that can see your screen and act on your machine does need more permissions than a normal application, but the useful question is not how many it asks for, it is what refusing each one costs. The other four are asked for by features that still work without them, just with less in them. Every permission is requested the first time you open the feature that needs it rather than in a wall at first launch, and refusing one disables exactly that feature and nothing else. Full Disk Access, the one most worth refusing by default, is required by nothing anywhere in the app and unlocks a single Labs feature.

Grux OS 3.0.0 · last checked 2026-09-30 · generated from the shipping release

All nine, and what saying no costs

PermissionRequired byWhat refusing costs you
MicrophoneMeetingsVoice input in Chat and Reactor
System audio captureMeetingsThe other half of the call, not your mic
Screen RecordingFocus logScreen context in Chat
CalendarCalendarThe agenda on Today, calendar tools in Chat
ContactsContactsContact lookup in Chat
AutomationNothingCommands, app control from Chat
AccessibilityNothingWindow and selection awareness, detail in Focus log
NotificationsNothingAlerts from Schedules, Workflows and Focus log
Full Disk AccessNothingOne Labs feature, and nothing else anywhere

The smallest useful install

One key and no permissions. Chat needs an Anthropic key or a local Ollama endpoint and nothing else. Pick no features during setup and the app asks for nothing beyond a model to answer with.

Why it is not sandboxed

ScreenCaptureKit, AppleEvents and cross-app microphone access do not exist inside the App Sandbox, so an app that captures your screen and drives other applications cannot be sandboxed and still do those things. That means the operating system's own path allowlist is not available either, and the filesystem boundary is enforced in Swift instead, in a single file.

The gap worth knowing about

All nine are declared and shown during setup, but the app does not yet check every one immediately before the system call that needs it. macOS still enforces them either way. What you may get is nothing back, rather than an explanation of which permission was missing.

Where to check this

ClaimSource
Grux OS declares nine macOS permissions, only five required by any featureREADME, Permissions
Every permission is requested the first time you open the feature that needs itREADME, Permissions
Full Disk Access is required by nothing, unlocks one Labs featureREADME, Permissions
A test parses the permission table from the README against the feature registryPermissionTableTests.swift
The filesystem boundary is enforced in Swift, in a single fileREADME, Permissions

Questions

Does Grux OS need Full Disk Access?
No. Full Disk Access is required by nothing in the app. It unlocks one Labs feature and nothing else anywhere.
When does Grux OS ask for permissions?
The first time you open the feature that needs one, not in a wall at first launch.
What happens if I refuse a permission?
That feature is disabled and nothing else changes. Refusing one never breaks another.
Download Grux 3.0.0 Read the source

Free, MIT licensed. macOS 14 or later, Apple silicon. 23.7 MB, signed and notarized by Apple. No account, no server, no subscription.