When DiskStory needs Full Disk Access
Full Disk Access is optional and manual. It expands visibility into protected locations but does not grant root access or bypass SIP.
Direct answer
Use Full Disk Access only when you want a protected-location scan across the startup disk. macOS requires you to add and enable DiskStory in System Settings; the app cannot grant itself access or modify the TCC database.
When this guide applies
- A startup-disk scan reports protected locations that could not be observed.
- You want Mail, Messages, Safari, Time Machine backup data, or other TCC-protected locations represented in coverage.
- You need to decide whether a broader scan is worth granting a privacy-sensitive permission.
Step-by-step review
Scan without the permission first
Use the normal accessible scope and inspect the coverage report before deciding whether broader visibility is necessary.
Open Privacy & Security
In System Settings, choose Privacy & Security → Full Disk Access. DiskStory cannot open this permission for itself.
Add and enable DiskStory manually
Use the system control to add the signed app, then enable it. macOS may require authentication or an app restart.
Rescan the same scope
Compare coverage against the earlier scan. Keep any remaining Unix, SIP, or Data Vault failures visible.
Revoke access when it is no longer needed
You can disable DiskStory in Full Disk Access from System Settings and continue using deliberately selected accessible folders.
Technical context
What the permission changes
It can make Mail, Messages, Safari, and other TCC-protected locations readable to the signed app. DiskStory checks conservatively by opening an existing protected file read-only and closing it without reading bytes.
What the permission does not change
It does not bypass root-only Unix permissions, System Integrity Protection, or Apple private Data Vault rules. Remaining failures stay visible in scan coverage.
What works without it
You can scan a folder you explicitly choose or the currently accessible startup-disk scope. DiskStory does not describe that partial result as a complete Mac scan.
Risks and actions to avoid
The permission is broad
Apple describes Full Disk Access as access to all files, including data from other apps and certain administrative settings. Grant it only to software you trust.
Broader access is not unlimited access
Full Disk Access does not turn an app into root and does not disable System Integrity Protection or every private Data Vault boundary.
A cleaner result may still be incomplete
Coverage must show remaining failures rather than interpreting fewer visible errors as proof that every byte was observed.
What the Omuuz product can—and cannot—do
What it can do
DiskStory can explain why broader access may improve scan coverage, detect whether protected reads remain unavailable, and work with a manually granted system permission.
What it cannot do
DiskStory cannot grant itself Full Disk Access, edit the TCC database, bypass SIP, or promise complete visibility after permission is enabled.
Product evidence
