Three layers of access.
A macOS permission lets Pommier use a system capability. Connecting an AI client lets it call Pommier’s tools. That client decides how to use the information it receives. These are separate decisions.
- 01 · macOSAllows access
Grants control which Apple data and app functions Pommier can use.
- 02 · PommierRuns the tool
A request reads or changes data through the relevant connector.
- 03 · Your AI clientReceives the result
Requested content returns to the client, including a cloud provider if you use one.
Local access is not a promise of local AI processing.
Pommier runs on your Mac. An AI client can still send prompts and returned Apple content to its provider. Review that client’s data handling before connecting it.
What each Mac permission allows.
Manage these grants under System Settings → Privacy & Security. Pommier’s permissions window links to the appropriate settings. Names and available access levels can vary by macOS version.
Full Disk Access
A broad macOS file-access grant, covering protected app data and other protected files. It is not limited to a single Pommier connector. Pommier uses protected local stores for Mail search and message files, Messages history, Notes reads and tags, and Reminders tags.
This is separate from permission to automate an app or use Calendar, Contacts and Reminders APIs. Declining it can prevent those local-store features from working; some Mail and Notes reads can use app automation instead.
Apple’s reference: Privacy & Security settings.
Automation
Allows Pommier to send Apple events to control another app. Each target has its own switch: Mail, Contacts, Messages and Notes. Depending on the app, this enables reads, edits, drafting or sending.
An Automation grant is not read-only and does not require a new macOS prompt for every tool call. It does not replace Full Disk Access for protected database reads.
Apple’s reference: Allow apps to automate and control other apps.
Calendars · Full access
Lets Pommier use EventKit to read calendars and events and make changes, including creating, updating and deleting events. Write access only cannot support calendar search or reading your schedule; the checklist displays that state separately.
Contacts
Lets Pommier use the Contacts framework to read and manage contact records and groups. If macOS grants Selected contacts only, access covers that selection rather than your whole address book. Contact notes and some CardDAV group operations also use Automation → Contacts.
Reminders · Full access
Lets Pommier use EventKit to read lists and reminders, create and edit them, mark them complete, and delete them. Reading real tag information from protected local stores is a separate file-access requirement.
The six apps, grant by grant.
This matches the connector breakdown in Pommier → Permissions…. A grant allows the underlying capability; it is not a per-tool approval.
Mail
- Local store access
- Fast email search, message files and attachment filters. Full Disk Access can enable this path.
- Automation → Mail
- Read through Mail when local files are unavailable; create drafts, change messages, and send replies or forwards when sending is enabled.
Calendar
- Calendars · Full access
- Find calendars and events, read details, and create, update or delete events. Full access is required for reads and writes.
Contacts
- Contacts
- Find people and groups, read details, and create, update or delete contacts within the access granted by macOS.
- Automation → Contacts
- Read and edit contact notes, and remove contacts from CardDAV groups.
Messages
- Local store access
- Read and search conversation history. The protected Messages database requires Full Disk Access.
- Automation → Messages
- Resolve participant names and send messages when requested. The email-sending switches below do not govern Messages.
Notes
- Local store access
- Fast note reads, search and tag information. Full Disk Access can enable the Notes store.
- Automation → Notes
- Create or change notes and folders; read through Notes when the local store is unavailable. Some operations can replace note content.
Reminders
- Reminders · Full access
- Read lists and reminders, and create, edit, complete or delete them.
- Local store access
- Read tags from protected Reminders stores. Ordinary reminders use the Reminders grant above.
Read the permissions checklist.
Open Permissions… from Pommier’s menu bar menu, or Set Up Permissions… from its connection window. Choose an Apple app to see the purpose and current status of each grant.
- Granted
- macOS reports that the relevant Calendar, Contacts, Reminders or Automation grant is available.
- Store accessible
- Pommier could open the protected local store for reading. The check opens and closes the file without reading its contents. It does not inspect the Full Disk Access switch or prove that every connector operation will work.
- Selected contacts only / Write access only
- A partial grant. The app displays it separately from full access because some tools need more than this permits.
- Access needed / Access denied
- Request access or review the grant in System Settings. An earlier denial may need to be changed there.
- Not available
- The target app may not be running, or the local store may not exist yet. Open the Apple app and finish account setup or syncing, then check again.
- Restricted by macOS / Not verified
- macOS has restricted access, or the check could not establish its state. A device administrator may need to review a restriction.
Request Access invokes the relevant macOS prompt and may open the target Apple app. Use Check again after making changes; returning from System Settings also refreshes the checklist.
A separate choice for email sending.
Mac permissions and Pommier’s sending settings work together. Under Permissions… → Mail → Sending, both settings start off:
- Allow sending email: permits local clients to send replies and forwards without you pressing Send.
- Also allow remote clients: permits registered remote clients to send too. Enabling it asks for confirmation, and it turns off when email sending is turned off.
When a send is disallowed, Pommier refuses it before it reaches Mail, records the refusal, and directs the client toward a draft. Draft creation remains available with the required Mail access.
Other writes have different boundaries.
Pommier includes tools that edit or delete data and can send Messages. It does not add an approval prompt to every call or offer a general per-tool filter. The email switches apply to email sending only. Configure your AI client’s confirmation behavior accordingly.
What request history keeps.
Request History stores tool names, supplied arguments, returned content, timing, status and source information on your Mac. It can contain private Apple content. It is not merely a list of metadata.
- The default saved-history limit is 50 MB, adjustable from 1 to 1,000 MB. The 7-day and 500-request retention limits also apply, with running requests protected.
- History lives in your account’s Application Support directory. The native history API uses a per-launch credential and rejects browser origins; it is not exposed through Remote Access.
- Authentication tokens, cookies and arbitrary request headers are not stored as history metadata. Tool arguments and results may still contain sensitive content.
- Remote source identities come from verified OAuth information. Local client names are self-reported and are not proof of identity.
- Clear History… removes completed records, not running requests or files you have exported. Clearing Pommier’s history does not remove information already received by an AI client.
Local storage and replay details
The history database is stored under ~/Library/Application Support/Apple Local MCP Companion/Request History/. The legacy directory name does not indicate a separate running app. Exports and transient database transaction files are outside the saved-history size cap.
Re-running a request requires confirmation and uses the current data, tools and permissions. A write may happen again. If a call times out, its outcome may be unknown and it can continue in the background; do not assume a timeout means no change occurred.
Change your mind at any time.
Find the right app
Use Review in Settings… in the permissions window. Check the running app path. For Full Disk Access, Show App in Finder selects that copy; add it with the + button in System Settings if needed.
Review or revoke the grant
Turn the relevant switch off under Pommier in Privacy & Security. Automation is per target app; Full Disk Access is shared by the connectors that use protected stores. Older entries may use the name Apple Local MCP Companion. The separate Apple MCP Companion app’s grants do not grant access to Pommier.
Quit and reopen Pommier
Use Quit and Reopen Pommier… to apply changes to the app and its server. macOS may also quit it when access is revoked. Connected clients may need to reconnect.
Revoking a grant stops capabilities that depend on it; another already-granted access path may still work. Stop Pommier to stop its services, or use the remote access controls to close remote access specifically.
Go a little deeper
Connecting from a cloud AI?
See how the public connection, OAuth checks and local-only controls fit together.
Read the remote access guide