Permissions

Orvial asks for powerful permission. You should know exactly why.

Accessibility permission sounds larger than “window manager”, and it is. Here is what Orvial expects to need, what it does not, and what happens when you take it away.

Orvial is in development. This page describes the permissions the product is being designed to need. The final list will be confirmed against the signed, notarised release before launch.

What Orvial asks for

Which macOS permissions does Orvial need?

Two of these are a plain no, and staying a no is part of the design.

Accessibility

Expected · required for the core product

Orvial expects to use the macOS Accessibility APIs to identify and control the windows you ask it to manage — to move, resize, minimise, restore or focus them. There is no narrower macOS interface that can do this.

macOS requires you to grant this permission explicitly, and it is powerful: it lets an approved app control accessible interface elements in other applications. That is exactly why Orvial should ask for it only after explaining what it is for, rather than on first launch.

Revoking it stops window control. Orvial is being designed to notice that loss, say so plainly, and explain how to restore access — not to fail silently or keep pretending it is in control.

Screen & System Audio Recording

Expected · not required

Normal Orvial workspace control should not require Screen Recording. If a later feature genuinely needs it, it should arrive as a separate, separately explained, optional permission.

Engine Lab — the internal test harness — may use its own observation instrumentation. Those privileges are not intended to reach the shipping application.

Full Disk Access

Expected · not required

Not for the core product. Broad file access should not be requested for convenience, and asking for it would undercut the reason to trust a tool that already controls your desktop.

Microphone

Future · only if you enable voice

No. If a voice surface is built later, the microphone should be requested only when you explicitly turn that feature on.

Automation and other-app permissions

Only where a shipping integration uses one

Only where a real, shipping integration needs it. Permissions should not be requested in advance because a roadmap feature might one day want them.

What it means for you

What can Orvial actually see?

Permission to control windows is not permission to read your work.

Accessibility permission lets Orvial identify and move windows. Orvial is being built so that what it keeps is the arrangement — which applications, which displays, which positions — rather than the contents of what you are working on.

The privacy design behind that is on privacy principles, and how the engine decides whether it is safe to act at all is on how it works.

Follow the build

Permissions get confirmed before launch.

When the first signed build exists, this page is updated against it.