Skip to main content

Requirements

Build

The test suite covers the monitoring core rather than the interface, so it runs headlessly and is safe to put in CI on a macOS runner.

Architecture

The monitoring core is a standalone, UI-free library shared by two executables — the SwiftUI menu-bar app and a headless CLI.
Because the core has no UI dependency it is fully unit-testable and backs the CLI directly — the same code path the app uses.

Permissions

The default feature set needs no special entitlements. It reads process accounting for your own user’s processes and sends signals to them — both ordinary unprivileged operations.
The practical consequence: the kill switch cannot stop processes owned by another user or by the system. Those return notPermitted. Deeper telemetry — real per-agent file access and outbound connections — would require an opt-in Endpoint Security system extension, which needs an Apple-granted entitlement plus notarisation. That is not in the default build.

Producing a distributable app

The sources drop straight into an Xcode app target. For a signed, distributable .app you will need to:
1

Wrap the sources in an Xcode app target

So the bundle can be code-signed and notarised.
2

Configure it as a menu-bar accessory

Set LSUIElement in the app target’s Info.plist so it runs without a dock icon.
3

Sign and notarise

Required for distribution outside your own machine — and required for native notifications to be delivered at all.
Full steps for the app target, system extensions, signing, notarisation, and first-run approval are in docs/BUILD.md in the repository.
Notifications need a signed app bundle. Sustained-critical alerts will not be delivered from an unsigned swift build binary, so a local development build will appear to have broken notifications when the feature is working correctly.

Configuration

Thresholds, the sustained-anomaly window, notification settings, and the auto-kill policy are all editable in-app and persisted through UserDefaults. You can also extend the catalog of watched agents: custom agents — name, process matchers, and log directories — can be added in Settings and are picked up by the monitor, the cost estimator, and the auto-kill list alike.

Auto-kill

Off by default, and enabling it requires an explicit confirmation. Once on, an agent that stays critical for the whole policy window is stopped automatically, with a per-agent cooldown, an optional allowlist, and a confirming notification.