Glossary
tccutil
The macOS command-line tool that resets TCC decisions, deleting rows from TCC.db for a service and optionally one bundle ID.
tccutil reset <Service> [bundle-id] deletes TCC decisions, for example tccutil reset ScreenCapture com.example.agent. The service name is given without the kTCCService prefix. Users and IT staff run it to fix permission problems; an intruder or cleanup script may run it to remove traces.
Deleted rows may survive for a while in TCC.db-wal or freed pages, and older database copies may exist in snapshots or backups. Never run it on a system before collection. See recovering removed TCC grants from the WAL.