What is TCC.db?
Transparency, Consent and Control (TCC) is the macOS framework that decides whether a program may use the camera, microphone, screen, keyboard events, accessibility APIs, protected folders, Full Disk Access or Apple Events automation. The daemon tccd records every standing decision in SQLite databases named TCC.db: one for the system and one per user.
Each row is a decision for one program (bundle ID or path) and one service, with the decision (allowed, denied, limited), why it was made, the program's code requirement and when the decision last changed. It is a permissions register, not a usage log.
Where it is stored
- /Library/Application Support/com.apple.TCC/TCC.db: system database (SIP- and TCC-protected), usually Full Disk Access, Accessibility, Screen Recording, Input Monitoring.
- ~/Library/Application Support/com.apple.TCC/TCC.db for each user: camera, microphone, folders, removable volumes, Automation and more.
- TCC.db-wal next to each database: the write-ahead log with recent changes and older copies of pages.
- /Library/Application Support/com.apple.TCC/MDMOverrides.plist: grants pushed by MDM configuration profiles (PPPC).
Why it matters in an investigation
- Shows which programs could read everything (Full Disk Access), watch the screen, log keystrokes or control the UI, including a terminal or a script host that everything else runs through.
- Dates the last change of each decision (Unix seconds, UTC): a burst of grants during an intrusion window is a strong pointer.
- Path-based clients in temporary, shared or hidden folders and ad-hoc signed code requirements point to dropped tools.
- The WAL and free pages can keep grants that were later removed with tccutil reset.
Limitations
- A row shows a decision, not its use: TCC.db does not log each camera activation or file read. Per-request evidence lives in the unified log (subsystem com.apple.TCC).
- last_modified is the last change only; the first grant time is lost when a row is updated.
- Removed rows survive only until SQLite reuses the space; a missing row does not prove a permission was never granted.
- auth_reason values and some columns (flags, pid, boot_uuid) are not documented by Apple; the tool shows raw values next to community interpretations.
How to get the files
- Copy the whole /Library/Application Support/com.apple.TCC folder and each user's ~/Library/Application Support/com.apple.TCC folder, keeping the paths, from a terminal with Full Disk Access (see “How to get your data”).
- Collect TCC.db-wal with each TCC.db; UAC's tcc.yaml and Aftermath copy TCC.db only.
- From an image, mount the Data volume read-only and archive the same folders.
FAQ
Are my TCC databases uploaded anywhere?
No. The parser is Rust compiled to WebAssembly and runs in a Web Worker in your browser. There is no upload endpoint; the tables, findings and exports are built locally.
Which macOS versions are supported?
Any layout of the access table: Mojave and Catalina (allowed, prompt_count), Big Sur to Ventura (auth_value, auth_reason, auth_version) and Sonoma and later (pid, pid_version, boot_uuid, last_reminded). Column names are read from each database's own schema, and unknown columns are shown as they are.
Do I need the -wal and -shm files?
Bring the -wal: it can contain the most recent decisions and older versions of rows, and the tool replays it like SQLite does. The -shm file is only an index of the WAL and is not needed.
What does auth_value 2 mean?
Allowed. 0 is denied, 1 unknown and 3 limited. On Mojave and Catalina the table had an allowed column (1 = allowed) instead, which the tool maps to the same decisions.
What is the csreq column?
A compiled code-signing requirement that identifies the program the decision applies to. The tool decodes it to text such as identifier "com.apple.Terminal" and anchor apple, and shows the team ID or the cdhash of ad-hoc signed code.
Can it recover deleted permissions?
Often, for recent changes: rows removed with tccutil reset or System Settings can survive in WAL frames, in the page versions the WAL replaced, and in free pages. They appear in the History tab until SQLite reuses the space.
About the parser
TCC Parser is an independent Rust implementation compiled to WebAssembly. It reads SQLite files itself, from the public file-format and WAL specifications (sqlite.org), so it can replay the -wal file, list what the WAL replaced and carve rows from free pages, which a normal SQLite query does not show. Columns are read from each database's own schema, so Mojave-era, Big Sur-era and Sonoma-and-later layouts are all decoded. Code requirements (csreq) are decoded to Apple's documented requirement language. auth_reason meanings are community-documented, not published by Apple; verify important conclusions on a test Mac of the same version and in the unified logs.