Agent access needs task-scoped expiry, not one extraordinary disk grant
Apple says future macOS releases will add controls when AI agents request Full Disk Access. Security teams should convert broad, durable consent into bounded task grants with expiry and review.

What happened
Apple said on 2 October that future macOS releases will introduce additional controls when AI agents request Full Disk Access, a permission that can expose files, mail, messages and browsing history.
Why it matters
A one-time operating-system prompt cannot express the changing purpose, data scope and duration of an autonomous task. Enterprises need a permission lifecycle that can be tested independently of any vendor interface.
Apple’s developer notice says Full Disk Access can sidestep normal privacy controls and expose files, mail, messages and browsing history. Apple plans additional controls in future macOS releases when AI agents request that permission, including an explicit user action. The notice is a product direction, not a complete security design or a dated deployment commitment.
Reuters reported that the change followed attention to Meta’s Muse agent and complaints about broad access. That context does not establish that a named product caused a confirmed breach. It does show why operating-system consent and agent orchestration can no longer be treated as separate control planes.
Replace the master grant with a task contract
A useful enterprise control should bind five fields: the requesting agent, the declared task, the data classes needed, the allowed actions and an expiry condition. The operating-system prompt may remain the final user decision, but policy should prevent an orchestrator from converting one approval into an indefinite capability.
Start with inventory. Record which agents can ask for extraordinary permissions, whether they can delegate to tools or subprocesses, and what evidence survives after the task. Test denial, partial grants, expiry, revocation and interrupted work. Preserve enough provenance to reconstruct access without copying unrelated personal content.
The Skills Intelligence Role Dictionary can assign who owns the task request, policy exception, user support and incident review.
The counterargument is practical: repeated prompts can train users to approve reflexively and make legitimate automation unreliable. That is why task templates and pre-approved low-risk scopes matter. A finance close, software build or research task can have a bounded permission profile, while novel combinations require an explicit exception.
Measure the permission lifecycle
Track broad grants created, median duration, revocations, requests exceeding their declared scope and tasks that fail safely after denial. Review whether the agent retained derived data after the original permission expired. An access control that ends while its copies persist is not complete.
This is not a claim that Full Disk Access should disappear. Some backup, security and accessibility workflows may need it. The immediate decision is to prohibit indefinite agent use of extraordinary disk access until a task, owner, scope, expiry and evidence path are recorded.