---
title: AclEntryMacOS type | Wartiva GraphQL API
description: A single macOS Access Control Entry on a file or directory. The subject is identified by AclSubject. Wartiva GraphQL API reference with examples.
url: https://wartiva.com/api-docs/types/acl-entry-mac-os.html
updated: 2026-10-07
---

File path sensors · GraphQL type

# `AclEntryMacOS` type

A single macOS Access Control Entry on a file or directory. The subject is identified by AclSubject.

## Fields

| Field Name | Description |
|---|---|
| `type` - [`AceType!`](https://wartiva.com/api-docs/types/ace-type.html) | The semantic class of the entry (allow / deny / audit). |
| `subject` - [`AclSubject!`](https://wartiva.com/api-docs/types/acl-subject.html) | The macOS ACL subject (UUID with resolved POSIX UID/GID) this entry applies to. |
| `permissions` - [`[AccessMask!]!`](https://wartiva.com/api-docs/types/access-mask.html) | The set of permissions granted or denied by this entry. |
| `flags` - [`[AceFlags!]!`](https://wartiva.com/api-docs/types/ace-flags.html) | The inheritance and audit flags on this entry. |

## Used by

- [`EndpointPathMacOS`](https://wartiva.com/api-docs/types/endpoint-path-mac-os.html) type: macOS-specific EndpointPath fields.

## Example

### Example

```json
{
  "type": "ACCESS_ALLOWED",
  "subject": AclSubject,
  "permissions": ["FILE_READ_DATA"],
  "flags": ["OBJECT_INHERIT"]
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
