Supported NSDataAccessSecurityPolicy schema and exact-owner allowlist on macOS

For macOS 26.7.1 (25G241), Xcode 27.0 (27A266a), and macOS SDK 27.0, we request the supported, exact Info.plist schema for NSDataAccessSecurityPolicy: its value type, literal key names and nesting, item types, and identity-selector grammar.

Can the policy allow only the owning process signed with a specific Team ID and signing identifier, without allowing all applications signed by that Team?

Are cdhash or designated-requirement selectors supported, and how do process and installer/package identities differ?

Please clarify the relationship to user consent and Full Disk Access exceptions, and confirm whether this configuration is supported for the macOS build listed above.

Please provide primary documentation or an authoritative schema, rather than a schema inferred from NSUpdateSecurityPolicy.

For context, it looks like NSDataAccessSecurityPolicy was mentioned once in a WWDC 2023 video (What's new in Privacy)..

And that's the extent of its documentation. I don't see any existing 3rd party or system apps that have ever used it.

Supported NSDataAccessSecurityPolicy schema and exact-owner allowlist on macOS
 
 
Q