---
title: PrivacyPermission type | Wartiva GraphQL API
description: A TCC (Transparency, Consent, and Control) database entry that tracks which applications have been granted access to protected resources such as camera.
url: https://wartiva.com/api-docs/types/privacy-permission.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL type

# `PrivacyPermission` type

A TCC (Transparency, Consent, and Control) database entry that tracks which applications have been granted access to protected resources such as camera, microphone, contacts, and full disk access.

## Fields

| Field Name | Description |
|---|---|
| `service` - [`PrivacyService!`](https://wartiva.com/api-docs/types/privacy-service.html) | The protected resource or service this permission controls. |
| `client` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The client application identifier (bundle ID or absolute path). |
| `clientType` - [`ClientIdentifierType!`](https://wartiva.com/api-docs/types/client-identifier-type.html) | How the client application is identified. |
| `authValue` - [`AuthValue!`](https://wartiva.com/api-docs/types/auth-value.html) | The current authorization value for this permission. |
| `authReason` - [`AuthReason!`](https://wartiva.com/api-docs/types/auth-reason.html) | The reason the authorization was granted or denied. |
| `authVersion` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | The TCC database schema version for this entry. |
| `policyID` - [`Int64`](https://wartiva.com/api-docs/types/int64.html) | The MDM policy identifier that set this permission, if applicable. |
| `indirectObjectIdentifierType` - [`ClientIdentifierType`](https://wartiva.com/api-docs/types/client-identifier-type.html) | The identifier type for the indirect object (e.g., target of Apple Events). |
| `indirectObjectIdentifier` - [`String`](https://wartiva.com/api-docs/types/string.html) | The identifier of the indirect object. |
| `indirectObjectCodeIdentity` - [`Binary`](https://wartiva.com/api-docs/types/binary.html) | The code signing identity of the indirect object. |
| `lastModified` - [`Time`](https://wartiva.com/api-docs/types/time.html) | When this permission entry was last modified. |
| `pid` - [`Int64`](https://wartiva.com/api-docs/types/int64.html) | The process ID that was granted the permission. |
| `pidVersion` - [`Int64`](https://wartiva.com/api-docs/types/int64.html) | The version of the process ID entry. |
| `bootUUID` - [`String`](https://wartiva.com/api-docs/types/string.html) | The boot UUID associated with this permission entry. |
| `lastReminded` - [`Time`](https://wartiva.com/api-docs/types/time.html) | When the user was last reminded about this permission. |

## Used by

- [`SystemSettingsMacOS`](https://wartiva.com/api-docs/types/system-settings-mac-os.html) type: macOS-specific system settings including power management, privacy permissions, backup configuration, and security settings.

## Example

### Example

```json
{
  "service": "K_TCC_SERVICE_ADDRESS_BOOK",
  "client": "xyz789",
  "clientType": "BUNDLE_IDENTIFIER",
  "authValue": "DENIED",
  "authReason": "ERROR",
  "authVersion": 987,
  "policyID": "-8589934592",
  "indirectObjectIdentifierType": "BUNDLE_IDENTIFIER",
  "indirectObjectIdentifier": "xyz789",
  "indirectObjectCodeIdentity": Binary,
  "lastModified": "2021-10-07T18:23:25.829Z",
  "pid": "-8589934592",
  "pidVersion": "-8589934592",
  "bootUUID": "xyz789",
  "lastReminded": "2021-10-07T18:23:25.829Z"
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
