Skip to content

Glossary

System Integrity Protection (SIP)

The macOS protection that blocks changes to system locations, including the system TCC.db, even by root. It does not block reads with Full Disk Access.

System Integrity Protection (SIP) prevents modification of protected system locations, even by root. The system TCC.db is SIP-protected, so a root process cannot simply write a grant into it while SIP is enabled. Reading it on a live system needs Full Disk Access, not SIP changes.

If SIP is disabled, direct edits of the system database become possible, so record SIP status in the case notes. See investigating TCC permission abuse.