Permissions
PedalScope asks macOS for three things, and only three. Each one is attached to something you started: a measurement you ran, a plugin you picked, a screenshot you asked for. Nothing here is accessed in the background, on a schedule, or while the app is merely open.
This page lists every prompt you can see, what it enables, exactly what stops working if you decline, and where to change your mind later.
Settings → Permissions shows all three side by side, in the same words: each one’s current standing, read silently — opening the pane never asks macOS for anything — with a button into the right System Settings pane where one exists. Where no switch exists anywhere (loading third-party plugins, below), the pane says so instead of showing a status it did not check.
One fact applies to everything on this page: macOS hands a changed permission to an app’s next launch, not the running one. So if you grant something in System Settings and PedalScope still reads it as absent, nothing went wrong and nothing was declined — the app offers Quit & Reopen PedalScope wherever that situation can arise, and the button does exactly what it says: quits, waits for the process to fully exit, and opens the same copy again.
Microphone — for hardware capture
What asks and when. macOS presents the microphone prompt the first time PedalScope opens an audio device — not the first time it records. That is usually your first hardware calibration, hardware measurement, or Live session, which do capture. But macOS ties the prompt to opening the device at all, so it can also appear the first time PedalScope only plays sound: the Play test tone button, Hear it illustration audio (its Play button, or its volume slider), or the pluck preview in Settings → Advanced. All three ask on purpose, once, before their first sound — the prompt arrives while you are looking at the control you just used, and whichever of them you use next does not ask again. None of those three records anything, and declining does not stop them — the tone, the illustrations and the preview play the same either way. Launching the app and browsing the library never trigger it, and neither does choosing a plugin — plugin measurement renders offline and creates no audio-device connection at all, so a plugin-only user who never plays a sound is never asked.
What it says before it asks. Pick the hardware source in the measure sheet and PedalScope states the permission’s standing right there, before you patch a cable or stage a level: whether it is granted, not yet asked for, or off. Nothing about that notice is a request — it is only the app telling you what it holds.
Why it is needed. macOS files all audio input under the Microphone permission, including a ¼″ instrument input on an audio interface — there is no separate “audio interface” permission to grant. PedalScope plays a test signal out of the interface and records what comes back; recording what comes back is the measurement.
What audio is captured. Only the interface input, only while a calibration, measurement, or Live session is actually running. There is no listening state outside a run, nothing is captured at launch, and the app has no background activity of any kind.
If you decline. Hardware capture stops — calibration, every hardware measurement kind, and Live mode. PedalScope says so plainly rather than failing quietly: the run reports that microphone access is off, with an Open Microphone Settings… button that takes you straight to the right pane. Everything that doesn’t capture keeps working: reading, comparing, exporting, hearing existing records, the test tone, the pluck preview, and plugin measurement, which renders offline through the plugin and never touches an input.
Changing it later. System Settings → Privacy & Security → Microphone, PedalScope’s switch. macOS asks you to quit and reopen the app when you change it there — a permission changed under a running app doesn’t reach it.
Loading a third-party plugin — a macOS consent, not a PedalScope one
What asks and when. The first time a plugin made by someone other than Apple loads in a given build of PedalScope, macOS itself asks: “Use of the requested Audio Unit(s) requires lowering the security settings for “PedalScope”. Are you sure you want to proceed?” — with two buttons, Lower Security Settings and Cancel. The prompt comes from the system, not from the app; PedalScope never sees your answer directly, only whether the plugin loaded. Apple’s own built-in Audio Units never ask.
Why it appears. Hosting an Audio Unit means running someone else’s code alongside the app. PedalScope loads every plugin out-of-process so a misbehaving plugin cannot take the app down, but macOS still wants your consent for the general capability. Lower Security Settings is the answer that loads the plugin.
If you decline. A Cancel is not remembered. macOS returns the load as cancelled, and the picker marks the row macOS consent declined with that sentence beside it. The row will not be tried again behind your back — a plain click on a marked row does nothing, by design — and the row’s Retry button is the way back: it loads the plugin again, and macOS asks again. If you press Retry and no panel appears, log out and back in, then Retry — the next paragraph says why. Hardware measurement is completely unaffected, and so is every plugin that already loaded.
If you never answer. Leaving the prompt standing is not the same as declining, and PedalScope does not treat it as though it were. Loading gives up after fifteen seconds, and the row is marked did not finish loading rather than failed — because from the app’s side those two are the same event, and a slow first load of a large plugin reaches the same deadline. A Cancel pressed after that deadline lands in the same mark. Either way the row waits for an explicit Retry, exactly as a declined one does. But an unanswered prompt has one consequence a Cancel does not: once macOS has shown the panel and had no answer, it stops showing it for the rest of your login session. Every later load — Retry included, and after quitting and reopening PedalScope — comes back cancelled with no panel, and the row reads macOS consent declined although you declined nothing. The way out is to log out of your Mac and back in, then press Retry: the panel comes back.
Changing it later. There is no Privacy & Security switch for this one, and the answer is not stored anywhere PedalScope can reach or show. To load a plugin you declined, press the marked row’s Retry in the plugin picker — macOS asks again (and if it does not, log out and back in first). Once you allow it, that build of PedalScope stays allowed; every PedalScope update asks once more, because macOS ties the consent to the exact build it was given for.
In Settings → Permissions this one reads not reportable. macOS offers no way for an app to check the consent’s standing, so PedalScope states that instead of guessing — and offers no button, because no switch exists for a button to reach.
Screen Recording — only for plugin-window screenshots
What asks and when. macOS asks the first time you press Grant… on the notice described below, or the first time you press Capture Screenshot in the plugin settings or Inspect window. Starting a measurement never asks: the automatic capture that happens when the plugin’s settings window is open checks whether the permission is already there, and skips itself — with a note beside the run — when it is not. A permission panel stops everything until someone clicks it, and a measurement must never be waiting on one.
You are told before you invest the work. Open a plugin’s settings window without this permission and a line appears under the plugin’s own view: screenshots need Screen Recording, granting it takes effect after a relaunch, doing it now costs nothing — and what the panel you are about to see actually offers (next paragraph). That is deliberate. The old behaviour said nothing until you pressed Capture Screenshot — which is after you have configured a chain — and then told you to quit and reopen the app. Your chain is saved as you configure it, so relaunching now loses nothing. Dismiss the line with its × if you do not want screenshots; it does not come back.
Why it is needed. Because plugins are hosted out-of-process, a plugin’s window is drawn by a system helper process. PedalScope’s own in-app renderer legally gets back one flat empty field from such a window — that is not a bug in any particular plugin, it is what a remote view is. The only way to obtain the real image is macOS’s window capture, which is gated behind Screen Recording.
What is captured — plainly. PedalScope captures its own window only: the specific window it opened for the plugin, cropped to the plugin’s view, at the moment you ask for a capture. It never records the screen, never captures another app’s window, never captures video, and captures nothing at any other time.
If you decline. The screenshot feature reports it, naming the remedy — nothing else degrades, and no measurement is delayed by a second. Plugin records still carry everything else they always did: the parameter tree, the state archive, the pre-check verdict, the version, the calibration chain. And if a capture ever comes back as a blank field, PedalScope detects that and tells you rather than storing a blank image as evidence.
After you press Grant… macOS shows its Screen Recording panel, and the panel has no Allow button: its two choices are Open System Settings and Deny. The grant is PedalScope’s switch in System Settings → Privacy & Security → Screen & System Audio Recording, which Open System Settings takes you to. Pressing Deny leaves that switch off and the app reading not granted — and nothing worse: the switch still works afterwards, and pressing Grant… shows the panel again. PedalScope tells you where you are in the sequence rather than leaving you to conclude the feature is broken: while you are in System Settings the app watches quietly for the grant, and the notice’s feedback line carries a Quit & Reopen PedalScope button — because whichever way macOS delivers the grant, a relaunch finishes the job cleanly, and clicking one button beats finding the app in the Applications folder mid-repair. If a capture is refused while the permission reads as granted, the same offer appears with the same explanation: the grant reaches the app at its next launch. At no point does the app tell you that you declined something — it cannot see your answer: measured on the bench, every reading the app can take is identical after a Deny and before any answer at all.
Changing it later. System Settings → Privacy & Security → Screen & System Audio Recording. A newly granted permission never applies to an already-running app — quit PedalScope and launch it again, or let the Quit & Reopen button do it.
If Settings says it's on and capture is still refused
This one is worth knowing because the fix is not obvious, and it is the one state the Settings switch does not clear. macOS keys this permission to an app’s code signature, not just its name — the grant it records carries the signing requirement of the copy that asked — so if two differently-signed copies of PedalScope have been on the Mac (a TestFlight build alongside another copy, say), the row in System Settings can read as granted while the copy you are running is still refused, and PedalScope itself reads not granted. The app’s own feedback after a refused capture names this case and the command below.
The ladder, in order:
Quit PedalScope and launch it again. A grant never applies to an already-running process, so this alone fixes the ordinary case.
Toggle PedalScope off and back on in Screen & System Audio Recording, then quit and relaunch.
Reset the permission and grant it fresh. In Terminal:
tccutil reset ScreenCapture com.phasedog.pedalscope, then relaunch PedalScope, press Grant… and switch it on in System Settings — macOS asks from scratch, and the new grant matches the copy you are actually running. On the bench, this is the step that worked.
A note on what this is. Screen Recording is a permission you grant, not a capability built into the app: PedalScope’s audited entitlement list is unchanged by the screenshot feature. Every grant PedalScope holds is listed on this page.
What PedalScope never asks for
Camera. Attaching a knob photo with an iPhone (Continuity Camera) is handled entirely by macOS and the phone — the finished image is handed to the app. PedalScope has no camera access and cannot request it.
Files and folders. File access happens through the standard open and save panels: you pick a file or folder, and the app receives that one. No Full Disk Access, no Desktop/Documents prompts, no folder scanning.
Network. The app talks to the App Store, and to nothing else. Buying or restoring the measurement unlock reaches Apple; so does the purchase check, though that one normally answers from a local cache and works with no connection at all. There are no accounts, no analytics and no telemetry. The guide you are reading, its figures and its audio are all bundled inside the app, and nothing is uploaded, phoned home, or analyzed remotely — your measurements stay on your Mac until you export them yourself.
Location, contacts, calendars, and app automation. Never requested.