Two switches. One belongs to macOS, the other to Meta. On Friday Apple said it will add controls to the first one, Full Disk Access, two weeks after columnist Jason Aten got a notification from Meta's Muse agent about an iMessage thread he never meant it to see. Meta's CTO David Singleton answered that Muse "can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled." Apple's note names no app. What it does is explain what the first switch was built for.
Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users' full knowledge and understanding.Apple Developer
Full Disk Access is a backup exception. It was built for software whose job is to copy every byte and understand none of them. A backup tool doesn't read your messages, it moves them. An agent does the opposite: it reads so it can understand and act, and what it does is decided at runtime by whoever is prompting it. The same grant meant one thing for a backup tool and means something else for an agent. So the failure isn't that users granted too much. It's that macOS gives them nothing smaller to grant.
Look at where Meta's defense puts the safeguard. The Messages connector is a setting inside Muse, a promise the app makes about what it will do with access the operating system has already handed over. Patrick Wardle made the technical point to Ars Technica's Dan Goodin: with Full Disk Access, "any (non-root file), is readable, browsing history, browser cookies, chats." The OS boundary is the whole disk. Anything finer than that is Meta's policy, enforced by Meta's code, inside an agent. Eleven days before Apple's note, Wardle disclosed a Muse configuration that let any code on the Mac, including commands slipped in through ClickFix attacks, take control of the assistant.
A toggle inside an agent holds exactly as long as nobody else is steering the agent.
Muse needed the whole disk because what it wanted has no smaller door. Message history lives in a database file under the user's Library folder, and macOS has no narrower permission for reading it. The only key to that file opens every other file too. Muse's connector is an attempt to supply granularity the OS never offered. Plenty of developers have made the same trade without the second switch: they granted their terminal Full Disk Access so some tool would stop complaining, and every agent launched from that terminal inherits it.
Apple's fix has a real case behind it. A consent prompt is how every platform handles this, and requiring "very explicit user action" for the big grant will stop people from granting it without noticing. Backup apps still need the whole disk, and Apple can't take it from them. But friction on one coarse grant only makes the trade more deliberate. It's still all or nothing. Someone who wants an agent to read their messages still has to hand over their browser cookies to get it. They'll just click harder first. The alternative is the thing Apple's note says Full Disk Access sidesteps: scoped permissions, like the ones macOS already has for contacts, calendars and photos, where the operating system holds the line and an injected prompt can't flip it. Agents need that for messages next.
A backup app gets the whole disk because it reads none of it. An agent reads everything it's given, so it should be given less. Right now it has two switches, and only one of them belongs to the operating system. Until Apple builds a smaller one, the other switch is a promise.