Omuuz

RunOrigin

See what may run in the background. Know where it came from.

An evidence-first, read-only macOS utility that groups visible LaunchAgents and LaunchDaemons by app or developer, shows the basis for ownership, and compares the current scan with the previous local snapshot.

Product facts

  • Read-only P0 — No pause, restore, deletion, configuration edits, or root helper
  • Scoped inspection — Applications plus five user, local, and system launchd locations
  • Graded ownership — Confirmed, Likely, or Unknown with path, bundle, signature, and Team ID evidence
  • Local history — JSON snapshots and user-initiated report export; no automatic upload

How it works

  1. Establish a baseline — Scan configured app roots and five launchd locations, then save the first local JSON snapshot without calling existing items new.
  2. Choose a view — Switch among Background Owners, Recent Changes, and Unresolved, with an explicit option to include system items.
  3. Search the evidence — Filter owner, Label, Bundle ID, Team ID, configuration path, executable path, or item type within the current view.
  4. Inspect the basis — Review ownership level, evidence, declared configuration, limited runtime observation, paths, and launch arguments.
  5. Rescan or export — Compare with the previous valid snapshot or export the current JSON report after checking paths and launch arguments.

What it does—and does not do

Product identity
RunOrigin is an internal working name, not a release-approved public brand
Current milestone
Internal read-only P0 with no public download, price, or licensing
Coverage
Five launchd directories; not every macOS background mechanism
Not covered
No comprehensive modern Login Items, Background Task Management, System Extensions, or Privileged Helpers
Read boundary
Reads app metadata and launchd configuration—not personal document contents
Ownership labels
Evidence grades, not Apple certification, necessity, safety, or malware verdicts
Status signals
Running and configured-enabled labels are limited observations, not authoritative system state
Snapshots
Local JSON; first scan is a baseline, later scans compare the previous valid snapshot
Export privacy
Reports are not anonymous and may contain host names, full paths, and launch arguments
Actions
No pause, restore, deletion, plist edits, privileged helper, or arbitrary shell execution
Network
No account, telemetry, analytics, cloud sync, or automatic upload path

RunOrigin Product guides

How RunOrigin explains a Mac background item

Questions answered from the product specification

What is RunOrigin?

RunOrigin is an internal read-only P0 macOS utility. It scans accessible LaunchAgent and LaunchDaemon configuration, explains ownership evidence, and compares the current scan with the previous local snapshot.

Can I download or buy RunOrigin now?

No. RunOrigin is still an internal working name with no public release package, confirmed price, licensing implementation, or verified production architecture.

What does RunOrigin scan?

It enumerates applications in three standard roots and inspects five user, local, and system launchd directories, reading plist configuration, program paths, launch arguments, and code-signature fields.

Can RunOrigin see every background item on my Mac?

No. Five launchd directories do not comprehensively cover modern Login Items, Background Task Management, System Extensions, Privileged Helpers, or every persistence mechanism.

What do Confirmed, Likely, and Unknown mean?

They are ownership-evidence grades based on stronger or weaker path, bundle, signature, Team ID, and system-domain rules. None is a safety or malware verdict.

Is an Unknown item malware or a broken path safe to delete?

No. Unknown means ownership evidence is insufficient, while a broken path only records a scan-time filesystem fact. The current version does not make a malware or deletion judgment.

Does RunOrigin modify background items?

No. It does not pause, restore, delete, edit plist files, install a privileged helper, or execute arbitrary shell commands. It writes only its own snapshots and user-requested exports.

What does RunOrigin read?

It reads app metadata and target launchd configuration. It does not recursively open or index personal documents, photos, mail, or other personal-file contents.

Are scan records uploaded?

Not automatically. The current implementation has no network, account, telemetry, or cloud-sync path. Local snapshots stay on the Mac.

Is an exported report anonymous?

No. It may contain the host name, installed apps, full paths, launch arguments, Bundle IDs, Team IDs, and coverage errors. Review and redact it before sharing.

Are Running and Configured as Enabled authoritative?

No. Running is a limited executable-path observation, and Configured as Enabled comes only from the plist Disabled field. Neither is a complete system-state view.

How does Recent Changes work?

The first scan establishes a baseline. Later scans compare with the most recent earlier valid snapshot and show added, removed, moved, and modified items without claiming exact cause or change time.

Does RunOrigin monitor continuously?

No. It creates snapshots at launch or on a requested rescan. There is no resident real-time monitoring service.

Which languages are supported?

The current app interface is Simplified Chinese only. English storefront copy does not mean the app has completed English localization.

Fact-check note

Facts are grounded in the RunOrigin product specification and the native app's scanner, ownership rules, snapshots, export, privacy, read-only, coverage, and release boundaries.

Current availability

Internal read-only P0 — Not publicly released or for sale