Glossary
auth_reason
The TCC.db column (Big Sur and later) giving the reason for a decision, such as user consent, user set, system set or MDM policy; community-documented values.
auth_reason records why a TCC decision was made. Apple does not document the values; the community mapping is 1 error, 2 user consent, 3 user set, 4 system set, 5 service policy, 6 MDM policy, 7 override policy, 8 missing usage string, 9 prompt timeout, 10 preflight unknown, 11 entitled, 12 app type policy.
It is the quickest way to separate a user's click from a policy, but treat it as a hypothesis and confirm on a test system of the same version. See the TCC access table across macOS versions.