Full Disk Access

Needed to read protected local macOS permission records. Veil reads these records; it never rewrites grants. If records are unavailable, that is unknown evidence, not denial.

Notifications

Optional at launch and used only for session start and stop alerts.

No Accessibility or Automation

The launch build does not require Accessibility or Automation permission for its core workflow.

Operational model

  • Local capability, grant-state, and running-state evidence kept distinct
  • Reviewable plans and explicit saved policies before app control
  • Verified results, including Needs You, Not Verified, and Not Controlled
  • Background Services are visible but not controlled in this version
  • End & Restore attempts to reopen eligible apps; it cannot recover their documents or unsaved work
  • Interrupted sessions offer recovery choices, not silent automatic restoration
  • No network observation, active-surveillance determination, or root helper