Which permissions does macOS ask for, and what breaks without them?
Two permissions Worktivity cannot work without, three more macOS asks for on its own, and exactly what stops working when you refuse each one.
- macOS
macOS does not let an app read what is on your screen, or what app you are in, without your say so. Worktivity asks for two permissions it cannot work properly without, and macOS asks for three more on its own along the way. This page goes through all of them: what each one is for, what stops working when you say no, and how to change your mind later.
The short version
- Screen Recording is needed for the periodic screenshot. Required.
- Accessibility is needed for the name of the app in front and the website you are on. Required.
- Automation is what macOS asks per browser, so Worktivity can read the address of the page you have open. Optional.
- Notifications let Worktivity show you reminders. Optional.
- Opening at login lets Worktivity start with your Mac. Optional.
Your hours are recorded either way. Nothing on this page can stop your timer from running.
Screen Recording
This is the permission macOS names after screen recording. Worktivity needs it for the periodic screenshot your organisation asked for.
Without it the screenshot is simply never taken. Your hours, the app you are in and your activity level keep being recorded as normal. Nobody is told the picture is missing, so the gap only shows up later in your reports.
This is the one permission that needs the app restarted after you grant it. There is a section on that further down.
Accessibility
This one lets Worktivity read which application is in front of you. In Firefox it also reads the address bar.
Without it every single record is filed under Accessibility permission required instead of a real app name. Your day still gets recorded, but the report is unusable: every minute looks like the same unknown application. This is the permission most worth getting right.
Accessibility is read live. Turn the switch on and Worktivity notices within a couple of seconds, with no restart.
Automation, once per browser
To read the address of the page you are on, Worktivity asks the browser itself. macOS treats one app asking another app a question as a separate permission, called Automation, and it asks about each browser separately the first time it happens.
The browsers this applies to are Safari, Google Chrome, Microsoft Edge, Opera and Vivaldi. Firefox is not one of them: its address is read through Accessibility instead, so Firefox never produces this prompt.
The prompt appears the first time you bring one of those browsers to the front while Worktivity is running, and it names both apps. Say yes once per browser and it is not asked again.
Without it the browser you are in is still recorded by name, but the website field is left empty rather than filled with a guess.
Worktivity cannot open the Automation list for you the way it can for the other two, so if you dismissed the prompt you have to go there yourself: System Settings, then Privacy & Security, then the Automation list, then the row named after Worktivity.
Notifications
Worktivity asks for this the very first time it opens, before you even sign in. It uses notifications for things like asking whether you are still working after a long idle stretch, and telling you when new tasks land in your list.
Without it those messages never appear. Tracking, screenshots and uploads are all unaffected. This one is genuinely optional.
Opening at login
Worktivity registers itself to open when you log in, so you do not have to remember to start it. macOS does not show a prompt for this. It either happens quietly or it waits for your approval in the list of items allowed to open at login, in System Settings under General.
Without it nothing breaks. You just have to open Worktivity yourself, and any time you forget is time that is not recorded.
When you are asked
The notification prompt comes first, at the very first launch. The two required permissions are asked for right after you sign in, before any tracking starts, in a short setup with three steps: a plain list of what is recorded, then one step per permission. Automation comes later, whenever you first use one of the browsers above.
On Windows and Linux this setup only shows the first step, because those systems ask for nothing.
In the setup, Continue stays inactive until the permission is on, and the reason is written just above the button. Both permission steps appear even when your organisation has screenshots turned off: the setup looks at the permission, not at the organisation setting.
The buttons in the setup
- Grant access asks macOS for the permission. The system window appears the first time only, so pressing it again opens the matching System Settings pane instead. Pressing it also registers Worktivity in the macOS permission list, and that matters: an app that has never asked does not appear in System Settings at all, so there is no switch to turn on.
- Open System Settings opens the matching pane directly, rather than the general privacy page.
- Quit and reopen Worktivity appears on the Screen Recording step only.
- See the step by step guide opens a longer walkthrough in your browser.
If System Settings cannot be opened for you, the step says so and points you at the guide instead.
Why Screen Recording needs a restart
macOS answers the Screen Recording question once for a running program and keeps that answer until the program ends. Turning the switch on does not change what Worktivity was already told, so the step keeps insisting the permission is off even though you just granted it. Quitting and reopening the app fixes it, and the button on that step does exactly that.
Accessibility, Automation and notifications all take effect immediately. Screen Recording is the only one with this quirk.
Granting a permission you refused earlier
Nothing is lost by saying no the first time. The setup is not shown again, but the live status of both required permissions sits in Settings, under Permissions, with a link straight to the system pane when one is missing.
- Open Worktivity and go to Settings.
- Find the Permissions section. Each row says whether it is granted.
- Use the link there to open the right pane in System Settings, and turn the switch on.
- If it was Screen Recording, quit Worktivity and open it again.
Taking a permission back
Every one of these can be switched off again in System Settings, in the same list you granted it in. Worktivity does not fight you on it and does not push you back into the setup. It keeps running with less: no screenshot without Screen Recording, no app names without Accessibility, no website without Automation.
What these permissions read, and what they do not
Granting Screen Recording does not mean your screen is being watched. A picture is taken only while your timer is running, only when you are not on a break, and only at the interval your organisation set. If your organisation has screenshots turned off, no picture is taken at all, permission or no permission.
When a screenshot is taken, it is a still picture of your main display, scaled down before it leaves your Mac. Other displays are not in it. If your organisation turned blurring on, it is blurred before it is sent, and there is no unblurred copy.
What these permissions do not give Worktivity:
- What you type. There is no keystroke recording of any kind.
- The full web address. Only the site is kept, for example
example.com, never the rest of the address after it. - Anything at all while your timer is stopped. Nothing is captured when you are clocked out or on a break.
- Your camera or your microphone. Worktivity never asks for either, and macOS would have to ask you separately if it did.
The full list of what a record carries is in what Worktivity collects.
The Mac App Store build
The Mac App Store build asks for exactly the same permissions as the build you download from the website. Which build belongs on which Mac is in the desktop app comparison.
Did this answer your question?
Related articles
How do I install and update the agent on a Mac?
The Mac App Store installs it and updates it; the direct .dmg is only for Macs too old for that build. Signing in leads straight into a three step setup that asks for two macOS permissions.
- macOS
Which desktop app should I install?
One app per platform, one web app that needs no install, and a table of what each of them can actually do.
- Web
- Windows
- macOS
- Linux
How do I update the desktop app?
Windows updates from a button inside the app, a Mac updates through the App Store, and Linux updates through apt or dnf.
- Windows
- macOS
- Linux
What happens if my computer goes offline?
Recording continues. The minutes queue up on your own machine and are sent in order once the connection is back.
- Windows
- macOS
- Linux
Still stuck?
Three different questions, three different places to ask them.