Skip to main content
MaestroRun is a small macOS launcher that holds a Full Disk Access grant for your scheduled scripts. You grant access once, to MaestroRun. It then runs only the scripts you approved, and hands them the grant. This page covers the Maestro plugin that installs it and sets it up. MaestroRun is an Encore Feature, off by default, and available on macOS only. On Windows and Linux the plugin is not offered.

The problem it solves

A script gets Full Disk Access through its interpreter. Homebrew and most version managers sign their interpreters ad hoc, and macOS pins a grant on an ad hoc binary to that one exact build. When Python or Node is upgraded, the grant is gone, and a LaunchAgent or cron job that worked yesterday fails with “Operation not permitted”. MaestroRun is signed with a Developer ID, so macOS stores its grant under the bundle identifier and the signing team. That grant survives every rebuild, move, and upgrade.

Setup

Open Settings > Plugins, select MaestroRun, and turn it on. Its Settings tab walks three steps. Maestro installs to ~/Applications/MaestroRun.app, which needs no administrator password. If you already put a copy in /Applications, Maestro uses and updates that one instead of adding a second.
Agents are told nothing about MaestroRun until both the install and the grant are done. Turning the plugin on is not enough. If you later switch Full Disk Access off, agents stop being told about it within a few minutes.

Using it

Ask any agent to move a scheduled script onto MaestroRun, for example: “my nightly Mail export lost Full Disk Access again, put it on MaestroRun”. The agent shows you the script path, the interpreter, and what protected data the script reads, and waits for your yes before it approves anything. You can also drive the launcher yourself:
A script runs only while its contents match what was approved. Edit it and run refuses with exit code 126 until you approve it again.

From the command line

Every button on the tile has a maestro-cli verb that reaches the same code. The Maestro app must be running.

What it protects, and what it does not

MaestroRun is a registry and a tamper check. It is not a sandbox.
  • A script that changed after approval does not run.
  • Every allowed and denied run is written to ~/Library/Logs/MaestroRun/maestro-run.log.
  • Everything an approved script starts inherits every privacy permission MaestroRun holds. Give MaestroRun only what your scripts need.
  • With the default per-user allowlist, another process running as you can approve its own script. Agents are instructed never to approve without your explicit yes, but that is a rule they follow, not something macOS enforces.
Read the MaestroRun threat model before you rely on it.

Turning it off

Turning the plugin off stops telling agents about MaestroRun. It does not remove MaestroRun.app, its Full Disk Access grant, or your approved scripts, because your scheduled jobs may depend on all three. To remove MaestroRun completely, switch it off under System Settings > Privacy & Security > Full Disk Access and move MaestroRun.app to the Trash.