Glossary
Gatekeeper
Gatekeeper is the macOS mechanism that checks downloaded apps for a valid Developer ID signature and notarization before they run.
Gatekeeper is the macOS component that decides whether software from outside the Mac App Store is allowed to run. When a user opens an app that was downloaded and marked with the com.apple.quarantine extended attribute, Gatekeeper verifies that the app is signed with a valid Developer ID certificate and has been notarized by Apple. It also checks that the code has not been modified since it was signed.
If the checks fail, macOS blocks the launch and explains why. Since macOS Sequoia, users can no longer bypass that block with the Control-click "Open" shortcut; instead they must review and allow the software in System Settings under Privacy & Security. Administrators can control Gatekeeper policy through MDM using the system policy payload, and can query its state with spctl --status.
Gatekeeper is a gate on first execution, not a continuous scanner. It works together with notarization, code signing and XProtect to reduce the chance of running known-malicious or tampered software.
Learn more in the Gatekeeper, XProtect and notarization guide.