Common permissions include the system proxy, startup at login, network extensions, VPN/TUN, notifications, and local-file access. Logs may record domains, IP addresses, rule matches, and errors. Disable unused services and startup items and revoke unnecessary permissions. When retaining logs, keep only the failure window and redact them.
Why the client needs these permissions
List the VPN/TUN, network-extension, startup, and file permissions granted to the client, and inspect whether logs or screenshots contain visited domains or credentials.
- Does the client need VPN, TUN, administrator, or network-extension permission?(See Download page)
- Are startup at login and background operation enabled?
- Do logs contain visited domains, node names, or subscription URLs?
- Did you install a root certificate or configuration profile from an unknown source?
Grant only required permissions
- Grant required permissions only to a trusted client
- Disable related permissions or services when TUN is not used
- Before sharing logs, redact domains, IP addresses, tokens, secrets, and node credentials
- Do not install certificates, profiles, or system extensions whose purpose you cannot explain
