Skip to content

Glossary

TCC (Transparency, Consent, and Control)

TCC is the macOS privacy framework that makes apps request user consent before accessing protected data, devices and system capabilities.

TCC, short for Transparency, Consent, and Control, is the macOS framework that governs app access to sensitive resources. Before an app can use the camera or microphone, record the screen, monitor keyboard input, control other apps, or read protected locations such as Mail data and other users' files, TCC asks the user for consent. Categories include Full Disk Access, Accessibility, Screen Recording, Input Monitoring, Automation, Camera and Microphone.

Decisions are handled by the tccd daemon and stored in TCC databases, one system-wide and one per user. System Integrity Protection protects those databases, so even root cannot simply edit them. Users review grants in System Settings under Privacy & Security, and tccutil reset clears decisions for a service.

Organizations can pre-configure some permissions with Privacy Preferences Policy Control (PPPC) profiles delivered through MDM. Some categories, such as camera and microphone, can only be denied by profile, not silently granted. Granting Full Disk Access or Accessibility sparingly is a core least-privilege practice.

See the TCC and privacy permissions guide for auditing and PPPC advice.