---
title: macOS permissions — what Omniscio asks for, and why
---

# macOS permissions — what Omniscio asks for, and why

## What it is

Plain-English reference for the macOS privacy prompts Omniscio can produce, what each one
is actually for, and what to do about the one notification that repeats.

## Where to find it

The prompts come from **macOS itself**, and only at the moment you first use the feature that needs them — never at startup and never all at once. Anything already granted is reviewed and changed in **System Settings → Privacy & Security**, where each permission lists Omniscio among its apps.

## How it behaves

### What Omniscio asks for

Every one of these is **opt-in and requested at the moment you use the feature** — never at
startup, never up front. The onboarding "Permissions" step is optional and skippable, and it
never triggers a macOS dialog unless you click.

| macOS permission | What Omniscio uses it for | Default |
|---|---|---|
| **Microphone** | Voice dictation (FlowVoice) and voice commands | Dictation is **off** |
| **Camera** | Only the webcam overlay on a screen recording | Off unless you pick a camera |
| **Audio capture** | Your Mac's audio while you record a screen capture or transcribe a meeting you started | Off |
| **Accessibility** | The global dictation hotkey, and typing dictated text at your cursor | Off |
| **Screen Recording** | Screen capture and meeting transcription | Off |
| **Automation → Terminal** | Opening a Terminal window when you sign in to an AI provider or install a developer tool | **Not optional** — core sign-in/setup flows use it |
| **Automation → System Events** | Pasting dictated text at your cursor, and reading your frontmost window title when naming a call | Only with dictation or meeting detection on |

**Omniscio does not control your system volume.** There is no volume or audio-output code in
the app at all. The fear is understandable: the System Events prompt asks permission to
control **System Events**, macOS's general scripting gateway — it *can* do far more than we
use it for, volume included. macOS offers no way to grant only "paste text", so the prompt
reads far broader than the actual use. Omniscio uses it for the two jobs above and nothing
else, and only if you turn dictation or meeting detection on.

**One Automation prompt is not optional, and it is usually the first one you see.** Signing
in to an AI provider, or installing a developer tool, opens a Terminal window to do it — and
macOS asks permission before one app may drive another. That prompt names **Terminal**, not
System Events, and it appears even with every optional feature switched off. It is narrow:
it lets Omniscio run the sign-in command in a window you can see.

**Bluetooth is not requested.** Older builds declared it by accident — it was inherited
boilerplate from the framework Omniscio is built on, with no code behind it. Removed, and a
build check now fails if it ever comes back.

### The repeating notification: "Omniscio was prevented from modifying apps on your Mac"

This one is different from all of the above, and it is the one people report.

**What it is.** It's the **App Management** permission. It appears as a notification with no
dialog and no reason — App Management is the only macOS privacy permission that behaves this
way, which is why it can fire over and over with nothing for you to answer.

**Why Omniscio is named.** macOS blames the app that *started* a command, not the command
itself. Omniscio runs commands on your behalf — installing a tool, cleaning a build folder,
tearing down a workspace. If any of those touches an installed app's files, macOS reports it
against Omniscio, even though Omniscio never touched that file.

**Omniscio never modifies your other apps**, and it never asks for App Management. There is
no way for an app to request that permission anyway.

**How to find out what it was.** Settings → Diagnostics → **Blocked by macOS App
Management** → *Check what was blocked*. macOS records the exact file in its own privacy log;
this reads it back and names the app, the command, and the path — for the last 24 hours.

**What to do.**

- If it was something you asked for (e.g. installing an app), allow the app that started it
  under  → System Settings → Privacy & Security → **App Management**. The card's *Open App
  Management settings* button takes you there.
- If it wasn't, you can ignore it. **Nothing was changed** — macOS blocked the write. The
  notification is a report, not damage.

One caveat the card states plainly: the macOS log line doesn't record which app was
responsible, so the list shows every App Management block on your Mac in that window. Some
may have nothing to do with Omniscio.

## Related

- Contract: `.claude/memory/contracts/macos-permission-surface-contract.md`
- Screen recording: [screen-recorder](screen-recorder.md) · Meeting capture: [meetings](meetings.md)
