Also worth reading John Gruber's complaints, over and above bugs: > But I don’t know a single expert Mac user who is not seriously annoyed by the heavy-handed security design of Catalina. Not one. Every single expert user I know is annoyed. That is a bad place for MacOS to be. MacOS 10.16 needs a serious course correction to fix this, and if 10.16 goes the opposite way — growing even more heavy-handed in restricting…
I'm kind of OK with "macOS Vista." I've wanted more restrictive and granular permissions for a long time. Web browsers don't need unrestricted access to the entire file system. Neither do games. Preview doesn't need to access the microphone. Word doesn't usually need to record the screen. PowerPoint should not be sending email or accessing the camera. TextEdit doesn't need access to my contacts or calendar. And I don…
Like Apple, you are thinking App-centrically. Stop. Apps are not the center of the users’ universe. The users’ own tasks are.
Therefore you need to think task-centrically—i.e. What does the user need/want to do?—and structure your security model to enable and support that.