← Mac Change Notes

Mac Full Disk Access vs Files and Folders

Files & Folders controls access to specific protected locations; Full Disk Access grants broader file access. Start in System Settings → Privacy & Security, inspect the app's existing settings, and match the requested access to the feature you actually need.

In this article

A request to open one document and a request to back up many locations are different jobs. The useful question is not simply whether an app is familiar. It is which data the feature needs, how you selected that data, and which other access restrictions still apply.

Check the location-specific setting first

Open Privacy & Security → Files & Folders and find the app. Review the locations listed beneath it. Apple's files and folders guide explains how to change access for individual listed locations.

Do this before following a generic instruction to enable Full Disk Access. If your problem concerns one folder, first identify that folder and the operation that fails. “Cannot open a document” is more useful evidence than “the app needs permissions.”

An app's absence from this list is not a complete access report. For example, the way you choose a document matters, as explained below. Do not assume that an empty list means an app cannot read any file.

Understand what each control covers

Apple's platform security reference distinguishes protected file locations from broader storage access. Its Files & Folders category includes Desktop, Documents, Downloads, network volumes, and removable volumes.

Control or actionWhat to checkWhat it does not establish
Files & FoldersThe app and the particular listed locationA complete inventory of every accessible file
Full Disk AccessWhether broader access is enabled for the intended appThat the app is trustworthy or has used that access
Choosing a document in an Open dialogThe exact item you selectedA reason to grant access to unrelated data
Finder file permissionsWhether your account can read or write the itemThe app's separate privacy authorization

Apple's Privacy & Security settings reference describes Full Disk Access as covering a wider range of data, including other apps' data such as Mail and Messages, Time Machine backups, and some administrative settings.

That broader scope is why the decision deserves a feature-specific explanation. A backup utility may need to work across many locations. A document editor opening a file you choose presents a different case. Those are starting points for investigation, not a universal allowlist of app categories.

Opening one file can be a separate access path

Try the app's ordinary File → Open workflow when your task is to use one document. Choose only the file or folder you intend the app to work with.

Apple's App Sandbox file-access documentation explains how standard system interactions can extend a sandboxed app's access to selected resources. Apps can also preserve appropriate access using security-scoped bookmarks.

This helps explain why a file can open even when you do not see an obvious folder-wide grant. It does not prove that the app can enumerate every neighboring file. Conversely, a background operation that tries to discover documents automatically may need a different access path from a user choosing one document.

Record which action succeeded. “I selected this file in the Open dialog” is a more precise observation than “the privacy settings are ignored.”

Full Disk Access does not remove every restriction

An access failure can have several causes. Apple's developer documentation separately identifies ordinary file permission bits, access control lists, System Integrity Protection, and data protection as possible restrictions. App Sandbox is also a separate part of the access model.

Do not treat Full Disk Access as an administrator account, a root privilege, or a universal repair button. Nor does a file-access setting grant camera or microphone permission. Those categories answer different questions.

For a failed operation, first verify the path and app identity. Check whether your own account can open the item in Finder. Then compare the failure with the app vendor's current instructions. A support article for a backup feature may not apply to a different feature in the same app.

If you are investigating a declaration shown by an inspection tool, our guide to entitlements versus current permissions explains why those findings need separate labels.

Use a decision record before broadening access

The following worksheet is an editorial decision aid based on the documented boundaries. It is not the result of changing permissions on a test Mac.

Your taskStart withRecord before considering broader access
Edit one documentSelect the document in the app's Open dialogThe chosen file and whether that operation succeeds
Use an app feature in DocumentsInspect the app's Documents entry in Files & FoldersThe feature, folder, current setting, and exact error
Back up multiple protected locationsRead the backup vendor's scope and setup instructionsWhich locations are included and why broader access is needed
Inspect another app's stored dataIdentify the data and the inspection purposeWhether a narrower export or supported workflow exists

Keep four short fields in your note: feature, location, current setting, observed result. If you later make a deliberate change, repeat the same operation and record the outcome. Avoid changing several privacy categories at once; that makes the result difficult to interpret.

A sensible stopping condition is that the intended feature works with the scope you chose. Success does not require turning every related switch on. If broader access still does not solve the problem, preserve the error and investigate the other restrictions rather than adding unrelated permissions.

When the target is application data, also check what an Application Support folder may contain. Being able to reach data and having a reason to remove it are separate decisions.

Keep declarations and permission decisions separate

VaultDog's app passport reads supported usage descriptions and signed entitlements, then groups those declarations with the installed application. Links to macOS privacy settings help you continue the review in the appropriate place.

Use that context to formulate a specific question about an app. VaultDog's declaration view does not establish that you granted Full Disk Access, show every file the app can read, or prove that a file was accessed. The getting started guide explains the passport workflow.

For this decision, your strongest record combines the exact app, the feature you need, the macOS setting you inspected, and the operation you observed. Keep each fact attached to its source.