DocsPermissions & data

DocsStart

Permissions & data

macOS access and the authorization of each action are separate controls. macOS grants the first once; the runtime checks the second on every request. This guide also lists where Mecum stores data and what a model can receive.

macOS permissions

A worker needs three macOS permissions to use this Mac. Mecum asks for them on the first launch, in the Mac Access sheet, and again from Settings → Computer → This Mac. Each row has its own Allow… button: the first time it shows the macOS prompt, after that it opens the matching page of System Settings. Text conversations work without any of them; a worker needs them only when it first uses your Mac.

PermissionPurpose
AccessibilityLets Mecum read interface elements and place the window it adopts. This is broader than read-only access.
Keyboard and Mouse ControlLets Mecum deliver clicks and keys to the adopted window. macOS keeps this switch in the Accessibility page, next to Accessibility itself.
Screen RecordingLets Mecum capture the adopted window for reading. macOS may group it under Screen & System Audio Recording; window capture does not record audio. A new grant reaches Mecum at its next launch only: when Mecum shows Restart Required, use Quit and Reopen.

Passive watching also requires Input Monitoring. The Watcher is an explicit capability: a client must be granted it and start it. Chrome connection authorization is separate from these permissions. Apple documents screen recording and Accessibility.

Two access boundaries

ControlWhat it governs
macOS permissionWhether the operating system lets Mecum capture the window, read its elements and deliver input.
Runtime authorizationWhether a request has a valid session, a current window and target, and a permitted action. Controls labelled delete, send, quit and the like are refused unless a person allowed destructive actions; a model cannot allow them.

Enabling one does not enable the other. There is no separate learning switch in this release: the Brain is written by what workers observe and do in the apps they use.

Where data goes

DataBoundary
Window imagesCaptured from the adopted window and processed on your Mac. In this release the tools return text: worker turns send no screenshots to a provider.
Window text and task contextIncluded in requests to the selected model. A remote provider receives what is sent to it.
App knowledgeOne file per application in ~/Library/Application Support/Mecum/Knowledge, with daily backups kept for 14 days and quarantined copies of unreadable files. Shared by workers and the command line. An external MCP client reaches it only with the Shared Brain and living memory capability; otherwise it has its own Brain.
Conversations and eventsWorkspace.store, a local database in the same folder. Command-line chats keep their transcripts in Conversations.
Provider credentialsAnthropic and Gemini API keys live in the login keychain and go only to that provider’s endpoint. Claude Code and Codex keep their own sign-in; Mecum stores no key for them. Ollama talks to the host you configure: local only when that host is local.
Web searchClaude Code and Codex workers can search the web and read pages. It is on by default; Settings → Chat → Web, “Workers can search the web”. Turning it off keeps workers from searching; it does not make a remote model local.
Text still reaches the model

Text visible in a window, task instructions and messages can reach the provider you selected, whether it runs on your Mac or not. The Mac processes images; the model receives text.

Change or revoke access

  1. Stop the response, or release the computer, before changing permissions.
  2. Revoke a permission in System Settings → Privacy & Security. A Screen Recording change reaches Mecum at its next launch.
  3. Check Settings → Computer → This Mac: a missing grant shows Allow… again.
  4. The next request that needs the computer reports the missing grant. The model cannot grant it.

Stopping a run does not undo changes already made. Revoking a permission does not delete saved knowledge or history. This release has no delete control: knowledge and history are files in the Mecum folder under Application Support, and removing them is something you do yourself, with Mecum closed, backups included.

If access is unavailable

SymptomCheck
No usable window observationConfirm the window exists and Screen Recording is granted. After a new grant, Quit and Reopen.
Target visible, action deniedRead the result: session, ownership, destructive label or action restrictions. Visibility alone does not authorize input.
No app knowledge yetThe Brain fills when a worker first uses that app. Open Settings → Computer → Brain to see what it holds.

Continue with Background for desktop sessions and Memory & Brain for what the Brain keeps.

Verified source

Checked against Mecum app source at main 524eb7f on October 1, 2026. UI labels and paths have not yet been checked against the signed release build.