Skip to content

Glossary

Plain-language definitions of the TCC terms used across the blog and the parser.

Apple Events automation
The TCC service kTCCServiceAppleEvents, which lets one app send commands to another, such as Terminal controlling Finder or System Events.
auth_reason
The TCC.db column (Big Sur and later) giving the reason for a decision, such as user consent, user set, system set or MDM policy; community-documented values.
auth_value
The TCC.db column (Big Sur and later) that holds the decision for a row: 0 denied, 1 unknown, 2 allowed, 3 limited.
client_type
The TCC.db column that says how the client is identified: 0 for a bundle ID such as com.apple.Terminal, 1 for an absolute path to a binary.
csreq (code requirement blob)
The TCC.db column holding a compiled code requirement (magic 0xFADE0C00) that a program must satisfy for the row to apply to it.
Designated requirement
The code requirement that identifies a signed program, printed by codesign -d -r-; compare it with the csreq stored in TCC.db.
Full Disk Access
The TCC permission kTCCServiceSystemPolicyAllFiles, which lets a program read protected user data such as Mail, Messages, Safari and the TCC databases.
PPPC and MDMOverrides.plist
Privacy Preferences Policy Control profiles let MDM pre-approve TCC services; the grants are reflected in MDMOverrides.plist next to the system TCC.db.
SQLite WAL (TCC.db-wal)
The write-ahead log next to TCC.db that holds recent changes and, often, earlier copies of pages containing removed or changed permission rows.
System Integrity Protection (SIP)
The macOS protection that blocks changes to system locations, including the system TCC.db, even by root. It does not block reads with Full Disk Access.
TCC.db
The SQLite databases where macOS stores privacy permission decisions: one system-wide and one per user, with an access table of client, service and decision.
TCC service (kTCCService)
The identifier in the service column of TCC.db naming the protected resource, such as kTCCServiceCamera, kTCCServiceAccessibility or kTCCServiceAppleEvents.
TCC (Transparency, Consent and Control)
The macOS framework that decides which programs may use privacy-sensitive resources such as the camera, screen, input, protected folders and other apps.
tccd
The macOS daemon that evaluates TCC permission requests, shows consent prompts and writes the decisions to the system and per-user TCC.db files.
tccutil
The macOS command-line tool that resets TCC decisions, deleting rows from TCC.db for a service and optionally one bundle ID.