In this article
A request to open one document and a request to back up many locations are different jobs. The useful question is not simply whether an app is familiar. It is which data the feature needs, how you selected that data, and which other access restrictions still apply.
Check the location-specific setting first
Open Privacy & Security → Files & Folders and find the app. Review the locations listed beneath it. Apple's files and folders guide explains how to change access for individual listed locations.
Do this before following a generic instruction to enable Full Disk Access. If your problem concerns one folder, first identify that folder and the operation that fails. “Cannot open a document” is more useful evidence than “the app needs permissions.”
An app's absence from this list is not a complete access report. For example, the way you choose a document matters, as explained below. Do not assume that an empty list means an app cannot read any file.
Understand what each control covers
Apple's platform security reference distinguishes protected file locations from broader storage access. Its Files & Folders category includes Desktop, Documents, Downloads, network volumes, and removable volumes.
| Control or action | What to check | What it does not establish |
|---|---|---|
| Files & Folders | The app and the particular listed location | A complete inventory of every accessible file |
| Full Disk Access | Whether broader access is enabled for the intended app | That the app is trustworthy or has used that access |
| Choosing a document in an Open dialog | The exact item you selected | A reason to grant access to unrelated data |
| Finder file permissions | Whether your account can read or write the item | The app's separate privacy authorization |
Apple's Privacy & Security settings reference describes Full Disk Access as covering a wider range of data, including other apps' data such as Mail and Messages, Time Machine backups, and some administrative settings.
That broader scope is why the decision deserves a feature-specific explanation. A backup utility may need to work across many locations. A document editor opening a file you choose presents a different case. Those are starting points for investigation, not a universal allowlist of app categories.
Opening one file can be a separate access path
Try the app's ordinary File → Open workflow when your task is to use one document. Choose only the file or folder you intend the app to work with.
Apple's App Sandbox file-access documentation explains how standard system interactions can extend a sandboxed app's access to selected resources. Apps can also preserve appropriate access using security-scoped bookmarks.
This helps explain why a file can open even when you do not see an obvious folder-wide grant. It does not prove that the app can enumerate every neighboring file. Conversely, a background operation that tries to discover documents automatically may need a different access path from a user choosing one document.
Record which action succeeded. “I selected this file in the Open dialog” is a more precise observation than “the privacy settings are ignored.”
Full Disk Access does not remove every restriction
An access failure can have several causes. Apple's developer documentation separately identifies ordinary file permission bits, access control lists, System Integrity Protection, and data protection as possible restrictions. App Sandbox is also a separate part of the access model.
Do not treat Full Disk Access as an administrator account, a root privilege, or a universal repair button. Nor does a file-access setting grant camera or microphone permission. Those categories answer different questions.
For a failed operation, first verify the path and app identity. Check whether your own account can open the item in Finder. Then compare the failure with the app vendor's current instructions. A support article for a backup feature may not apply to a different feature in the same app.
If you are investigating a declaration shown by an inspection tool, our guide to entitlements versus current permissions explains why those findings need separate labels.
Use a decision record before broadening access
The following worksheet is an editorial decision aid based on the documented boundaries. It is not the result of changing permissions on a test Mac.
| Your task | Start with | Record before considering broader access |
|---|---|---|
| Edit one document | Select the document in the app's Open dialog | The chosen file and whether that operation succeeds |
| Use an app feature in Documents | Inspect the app's Documents entry in Files & Folders | The feature, folder, current setting, and exact error |
| Back up multiple protected locations | Read the backup vendor's scope and setup instructions | Which locations are included and why broader access is needed |
| Inspect another app's stored data | Identify the data and the inspection purpose | Whether a narrower export or supported workflow exists |
Keep four short fields in your note: feature, location, current setting, observed result. If you later make a deliberate change, repeat the same operation and record the outcome. Avoid changing several privacy categories at once; that makes the result difficult to interpret.
A sensible stopping condition is that the intended feature works with the scope you chose. Success does not require turning every related switch on. If broader access still does not solve the problem, preserve the error and investigate the other restrictions rather than adding unrelated permissions.
When the target is application data, also check what an Application Support folder may contain. Being able to reach data and having a reason to remove it are separate decisions.
Keep declarations and permission decisions separate
VaultDog's app passport reads supported usage descriptions and signed entitlements, then groups those declarations with the installed application. Links to macOS privacy settings help you continue the review in the appropriate place.
Use that context to formulate a specific question about an app. VaultDog's declaration view does not establish that you granted Full Disk Access, show every file the app can read, or prove that a file was accessed. The getting started guide explains the passport workflow.
For this decision, your strongest record combines the exact app, the feature you need, the macOS setting you inspected, and the operation you observed. Keep each fact attached to its source.


