Glossary
Plain-language definitions of the TCC terms used across the blog and the parser.
- Apple Events automation
- The TCC service kTCCServiceAppleEvents, which lets one app send commands to another, such as Terminal controlling Finder or System Events.
- auth_reason
- The TCC.db column (Big Sur and later) giving the reason for a decision, such as user consent, user set, system set or MDM policy; community-documented values.
- auth_value
- The TCC.db column (Big Sur and later) that holds the decision for a row: 0 denied, 1 unknown, 2 allowed, 3 limited.
- client_type
- The TCC.db column that says how the client is identified: 0 for a bundle ID such as com.apple.Terminal, 1 for an absolute path to a binary.
- csreq (code requirement blob)
- The TCC.db column holding a compiled code requirement (magic 0xFADE0C00) that a program must satisfy for the row to apply to it.
- Designated requirement
- The code requirement that identifies a signed program, printed by codesign -d -r-; compare it with the csreq stored in TCC.db.
- Full Disk Access
- The TCC permission kTCCServiceSystemPolicyAllFiles, which lets a program read protected user data such as Mail, Messages, Safari and the TCC databases.
- PPPC and MDMOverrides.plist
- Privacy Preferences Policy Control profiles let MDM pre-approve TCC services; the grants are reflected in MDMOverrides.plist next to the system TCC.db.
- SQLite WAL (TCC.db-wal)
- The write-ahead log next to TCC.db that holds recent changes and, often, earlier copies of pages containing removed or changed permission rows.
- System Integrity Protection (SIP)
- The macOS protection that blocks changes to system locations, including the system TCC.db, even by root. It does not block reads with Full Disk Access.
- TCC.db
- The SQLite databases where macOS stores privacy permission decisions: one system-wide and one per user, with an access table of client, service and decision.
- TCC service (kTCCService)
- The identifier in the service column of TCC.db naming the protected resource, such as kTCCServiceCamera, kTCCServiceAccessibility or kTCCServiceAppleEvents.
- TCC (Transparency, Consent and Control)
- The macOS framework that decides which programs may use privacy-sensitive resources such as the camera, screen, input, protected folders and other apps.
- tccd
- The macOS daemon that evaluates TCC permission requests, shows consent prompts and writes the decisions to the system and per-user TCC.db files.
- tccutil
- The macOS command-line tool that resets TCC decisions, deleting rows from TCC.db for a service and optionally one bundle ID.