DocsStart
Permissions & data
macOS access and the authorization of each action are separate controls. macOS grants the first once; the runtime checks the second on every request. This guide also lists where Mecum stores data and what a model can receive.
macOS permissions
A worker needs three macOS permissions to use this Mac. Mecum asks for them on the first launch, in the Mac Access sheet, and again from Settings → Computer → This Mac. Each row has its own Allow… button: the first time it shows the macOS prompt, after that it opens the matching page of System Settings. Text conversations work without any of them; a worker needs them only when it first uses your Mac.
| Permission | Purpose |
|---|---|
| Accessibility | Lets Mecum read interface elements and place the window it adopts. This is broader than read-only access. |
| Keyboard and Mouse Control | Lets Mecum deliver clicks and keys to the adopted window. macOS keeps this switch in the Accessibility page, next to Accessibility itself. |
| Screen Recording | Lets Mecum capture the adopted window for reading. macOS may group it under Screen & System Audio Recording; window capture does not record audio. A new grant reaches Mecum at its next launch only: when Mecum shows Restart Required, use Quit and Reopen. |
Passive watching also requires Input Monitoring. The Watcher is an explicit capability: a client must be granted it and start it. Chrome connection authorization is separate from these permissions. Apple documents screen recording and Accessibility.
Two access boundaries
| Control | What it governs |
|---|---|
| macOS permission | Whether the operating system lets Mecum capture the window, read its elements and deliver input. |
| Runtime authorization | Whether a request has a valid session, a current window and target, and a permitted action. Controls labelled delete, send, quit and the like are refused unless a person allowed destructive actions; a model cannot allow them. |
Enabling one does not enable the other. There is no separate learning switch in this release: the Brain is written by what workers observe and do in the apps they use.
Where data goes
| Data | Boundary |
|---|---|
| Window images | Captured from the adopted window and processed on your Mac. In this release the tools return text: worker turns send no screenshots to a provider. |
| Window text and task context | Included in requests to the selected model. A remote provider receives what is sent to it. |
| App knowledge | One file per application in ~/Library/Application Support/Mecum/Knowledge, with daily backups kept for 14 days and quarantined copies of unreadable files. Shared by workers and the command line. An external MCP client reaches it only with the Shared Brain and living memory capability; otherwise it has its own Brain. |
| Conversations and events | Workspace.store, a local database in the same folder. Command-line chats keep their transcripts in Conversations. |
| Provider credentials | Anthropic and Gemini API keys live in the login keychain and go only to that provider’s endpoint. Claude Code and Codex keep their own sign-in; Mecum stores no key for them. Ollama talks to the host you configure: local only when that host is local. |
| Web search | Claude Code and Codex workers can search the web and read pages. It is on by default; Settings → Chat → Web, “Workers can search the web”. Turning it off keeps workers from searching; it does not make a remote model local. |
Text visible in a window, task instructions and messages can reach the provider you selected, whether it runs on your Mac or not. The Mac processes images; the model receives text.
Change or revoke access
- Stop the response, or release the computer, before changing permissions.
- Revoke a permission in System Settings → Privacy & Security. A Screen Recording change reaches Mecum at its next launch.
- Check Settings → Computer → This Mac: a missing grant shows Allow… again.
- The next request that needs the computer reports the missing grant. The model cannot grant it.
Stopping a run does not undo changes already made. Revoking a permission does not delete saved knowledge or history. This release has no delete control: knowledge and history are files in the Mecum folder under Application Support, and removing them is something you do yourself, with Mecum closed, backups included.
If access is unavailable
| Symptom | Check |
|---|---|
| No usable window observation | Confirm the window exists and Screen Recording is granted. After a new grant, Quit and Reopen. |
| Target visible, action denied | Read the result: session, ownership, destructive label or action restrictions. Visibility alone does not authorize input. |
| No app knowledge yet | The Brain fills when a worker first uses that app. Open Settings → Computer → Brain to see what it holds. |
Continue with Background for desktop sessions and Memory & Brain for what the Brain keeps.
Checked against Mecum app source at main 524eb7f on October 1, 2026. UI labels and paths have not yet been checked against the signed release build.
