Select Application
Choose an unprotected app to bring under Zero Trust file access control.
Currently unprotected — full filesystem access
This app currently has no file access restrictions. A learning period will observe its normal behavior before restrictions take effect.
Review Access Restrictions
After protection is applied, the app's file access will be significantly reduced. No developer action is required.
Currently Accessible
~/Library/Application Support/
~/workspace/ (read+write)
Will Be Accessible
~/workspace/ (read+write)
Additional paths added during learning period
Blast radius: Working directory only
5 high-risk access paths will be silently contained after the learning period.
Choose Rollout
Select how broadly to deploy protection. You can expand coverage later at any time.
All 247 endpoints (immediate)
Protection applied fleet-wide. Fastest time-to-value.
Engineering group only (98 endpoints)
Staged rollout to your primary developer group first.
Single endpoint for testing
Validate protection behavior before broader deployment.
Confirm Protection
Review and apply. No developer action will be required.
Protection will be applied silently to endpoints. No developer action required. No tickets will be generated.
Learning period begins immediately — 14 days of observation
Restrictions take effect automatically after learning completes
5 high-risk access paths will be contained with zero user friction
Developers will see their app listed as 'Protected' in their self-service portal. All restrictions are fully auditable and reversible.
Summary
Application
Deployment scope
Paths to be contained
5 high-risk paths
Developer tickets
0