How macOS actually works
It sounds alarming and is routinely misunderstood. Here is precisely what it covers.
A macOS privacy control. By default, apps cannot read certain protected locations even though your user account can — Mail, Messages, Safari history, Time Machine backups, and some system areas.
Full Disk Access removes that restriction for one specific app.
/System, which SIP protects independentlyfind and ls to work everywhere without permission errorsSystem Settings → Privacy & Security → Full Disk Access, then the + button, or the toggle beside an app already listed. The app must be quit and reopened afterwards — this catches people constantly, because nothing tells you and the app simply keeps failing.
The honest test: does the app's core function require reading files it cannot currently reach? A search tool that promises to find everything genuinely does. A weather widget does not.
Distribution matters too. Because sandboxed apps cannot receive this permission, any tool that needs it must be distributed outside the Mac App Store — which is why signed, notarised direct downloads exist in this category.
Same panel, toggle off. The app stops seeing protected locations immediately, though it may need restarting to notice.
It is a real privilege and worth granting deliberately. It does not grant admin rights, and it is per-app and revocable at any time.
The app must be quit and relaunched. macOS does not apply the change to a running process.
Everywhere keeps track of every file on your Mac — including the folders Spotlight hides and drives you have unplugged. Free for a day, then $19 once.
Download for Mac