RunOrigin
See what may run in the background. Know where it came from.
An evidence-first, read-only macOS utility that groups visible LaunchAgents and LaunchDaemons by app or developer, shows the basis for ownership, and compares the current scan with the previous local snapshot.
Product facts
- Read-only P0 — No pause, restore, deletion, configuration edits, or root helper
- Scoped inspection — Applications plus five user, local, and system launchd locations
- Graded ownership — Confirmed, Likely, or Unknown with path, bundle, signature, and Team ID evidence
- Local history — JSON snapshots and user-initiated report export; no automatic upload
How it works
- Establish a baseline — Scan configured app roots and five launchd locations, then save the first local JSON snapshot without calling existing items new.
- Choose a view — Switch among Background Owners, Recent Changes, and Unresolved, with an explicit option to include system items.
- Search the evidence — Filter owner, Label, Bundle ID, Team ID, configuration path, executable path, or item type within the current view.
- Inspect the basis — Review ownership level, evidence, declared configuration, limited runtime observation, paths, and launch arguments.
- Rescan or export — Compare with the previous valid snapshot or export the current JSON report after checking paths and launch arguments.
What it does—and does not do
- Product identity
- RunOrigin is an internal working name, not a release-approved public brand
- Current milestone
- Internal read-only P0 with no public download, price, or licensing
- Coverage
- Five launchd directories; not every macOS background mechanism
- Not covered
- No comprehensive modern Login Items, Background Task Management, System Extensions, or Privileged Helpers
- Read boundary
- Reads app metadata and launchd configuration—not personal document contents
- Ownership labels
- Evidence grades, not Apple certification, necessity, safety, or malware verdicts
- Status signals
- Running and configured-enabled labels are limited observations, not authoritative system state
- Snapshots
- Local JSON; first scan is a baseline, later scans compare the previous valid snapshot
- Export privacy
- Reports are not anonymous and may contain host names, full paths, and launch arguments
- Actions
- No pause, restore, deletion, plist edits, privileged helper, or arbitrary shell execution
- Network
- No account, telemetry, analytics, cloud sync, or automatic upload path
RunOrigin Product guides
How RunOrigin explains a Mac background itemQuestions answered from the product specification
What is RunOrigin?
RunOrigin is an internal read-only P0 macOS utility. It scans accessible LaunchAgent and LaunchDaemon configuration, explains ownership evidence, and compares the current scan with the previous local snapshot.
Can I download or buy RunOrigin now?
No. RunOrigin is still an internal working name with no public release package, confirmed price, licensing implementation, or verified production architecture.
What does RunOrigin scan?
It enumerates applications in three standard roots and inspects five user, local, and system launchd directories, reading plist configuration, program paths, launch arguments, and code-signature fields.
Can RunOrigin see every background item on my Mac?
No. Five launchd directories do not comprehensively cover modern Login Items, Background Task Management, System Extensions, Privileged Helpers, or every persistence mechanism.
What do Confirmed, Likely, and Unknown mean?
They are ownership-evidence grades based on stronger or weaker path, bundle, signature, Team ID, and system-domain rules. None is a safety or malware verdict.
Is an Unknown item malware or a broken path safe to delete?
No. Unknown means ownership evidence is insufficient, while a broken path only records a scan-time filesystem fact. The current version does not make a malware or deletion judgment.
Does RunOrigin modify background items?
No. It does not pause, restore, delete, edit plist files, install a privileged helper, or execute arbitrary shell commands. It writes only its own snapshots and user-requested exports.
What does RunOrigin read?
It reads app metadata and target launchd configuration. It does not recursively open or index personal documents, photos, mail, or other personal-file contents.
Are scan records uploaded?
Not automatically. The current implementation has no network, account, telemetry, or cloud-sync path. Local snapshots stay on the Mac.
Is an exported report anonymous?
No. It may contain the host name, installed apps, full paths, launch arguments, Bundle IDs, Team IDs, and coverage errors. Review and redact it before sharing.
Are Running and Configured as Enabled authoritative?
No. Running is a limited executable-path observation, and Configured as Enabled comes only from the plist Disabled field. Neither is a complete system-state view.
How does Recent Changes work?
The first scan establishes a baseline. Later scans compare with the most recent earlier valid snapshot and show added, removed, moved, and modified items without claiming exact cause or change time.
Does RunOrigin monitor continuously?
No. It creates snapshots at launch or on a requested rescan. There is no resident real-time monitoring service.
Which languages are supported?
The current app interface is Simplified Chinese only. English storefront copy does not mean the app has completed English localization.
Fact-check note
Facts are grounded in the RunOrigin product specification and the native app's scanner, ownership rules, snapshots, export, privacy, read-only, coverage, and release boundaries.
Current availability
Internal read-only P0 — Not publicly released or for sale