| ▲ | Someone 9 hours ago | |||||||
> This system is annoying but manageable on your primary Mac; it’s a disaster on a headless Mac running agents, for two reasons. First, agents write new programs all of the time, and in my case, those programs need access to devices on my network (SMB shares, for example, trigger a TCC warning). What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction. Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too. And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too. Or would it mean agents need to do some special thing to launch tools? | ||||||||
| ▲ | lenkite 9 hours ago | parent [-] | |||||||
I think some standards org needs to define comprehensive agent permissions model first before the OS raises the abstraction to agent level authorization. | ||||||||
| ||||||||