HardenMac — Mac Exposure Map
See what your Mac can reach. Decide what to review first.
Free Edition — Version 1.0
Checked: August 9, 2026
Your Mac may be connected to far more than the files stored on it. A browser profile can keep you signed in to email, cloud drives, financial accounts, work systems, and admin tools. An extension or AI tool may be able to read pages, reach local files, use a connected account, or take actions you approve. One control account may be able to reset several others.
The purpose of this worksheet is to make those connections visible.
If you just completed the Mac Exposure Check, this worksheet turns your answers into a practical map. If you started here, it also works on its own.
When you finish, you will know:
- what is connected to your Mac;
- which connections matter most;
- which connections could have wider consequences;
- what you still do not know; and
- what to review first.
This is an exposure-mapping worksheet, not a security scan. It cannot tell you whether your Mac is safe, infected, monitored, or compromised. It does not prove that anyone or anything accessed your information.
Privacy note: Do not write passwords, passkeys, recovery codes, full financial account numbers, API keys, private client information, or other secrets in this worksheet. Use labels such as “primary email,” “main bank,” or “Client A portal.”
How to Complete Your Map
Allow about 20–30 minutes for a first pass. You do not need to know every answer.
1. Begin with what you remember
List the accounts, profiles, services, files, tools, and permissions that come to mind immediately. Do not stop to investigate every item yet.
2. Check the places where connections hide
Look at:
- every browser and browser profile you use;
- extensions in each browser;
- apps installed on the Mac;
- cloud folders visible in Finder;
- accounts that stay signed in;
- connected-app pages inside important accounts;
- System Settings → Privacy & Security;
- System Settings → General → Login Items & Extensions;
- System Settings → General → Sharing; and
- System Settings → General → Time Machine.
Menu names can vary by macOS version. If a setting has moved, search for its name inside System Settings.
3. Map the connection, not every detail
For each item, record:
- What is it?
- How does the Mac reach it?
- What could it reach, reveal, reset, share, or control?
- What consequence level fits?
- Is anything still unknown?
4. Use these connection labels
Choose every label that applies.
| Label | Meaning |
|---|---|
| On Mac | The app, file, credential, or data is stored locally. |
| Signed in | A browser or app has an active account session. |
| Synced | Files, passwords, messages, photos, or settings move between the Mac and a cloud service. |
| Connected | An app or service has been linked to another account, sometimes through “Sign in with…” or OAuth. |
| Permitted | An app has macOS or browser permission to read, observe, or control something. |
| Can act | A tool, automation, or agent can send, edit, delete, publish, purchase, deploy, or perform another action. |
| Can recover | The account, device, email address, or phone number can reset or recover another account. |
| Unknown | You cannot yet confirm the connection, permission, session, owner, purpose, or reach. |
5. Classify by consequence, not by fear
This map does not calculate a scientific security score. Use the consequence labels below to create a sensible review order.
Consequence Classification
High consequence
Use High consequence when an item could do one or more of the following if its access were misused:
- reset or unlock other important accounts;
- expose a password vault, recovery method, passkeys, or recovery codes;
- move money, change payment details, or access tax or identity information;
- reach work, client, customer, employee, or admin systems;
- expose highly sensitive local or cloud files;
- publish, deploy, delete, or make changes with broad impact; or
- combine broad reading access with the ability to act.
Common examples include a primary email account, password manager, Apple Account, business administrator account, main financial account, or an AI agent connected to important systems with action permissions.
Medium consequence
Use Medium consequence when an item contains meaningful private information or ongoing access, but does not appear to control a wider part of your digital life.
Examples may include a personal cloud folder, a messaging account, a browser profile with ordinary sessions, a social account, or a tool with access to a limited set of files.
Lower consequence
Use Lower consequence when the connection is narrow, replaceable, and does not appear to contain sensitive information, active privileged access, or a path into more important systems.
Lower consequence does not mean “safe forever.” It means “review after the items with wider effects.”
Unknown
Use Unknown whenever you cannot confidently answer what an item is, why it is present, what it can access, whether it is still connected, or who depends on it.
Unknown does not automatically mean high consequence. It does mean the item is unresolved. Review unknowns connected to control accounts, broad permissions, work/client systems, financial access, or tools that can act before you spend time on known lower-consequence items.
Quick classification test
Ask:
If this one connection were unavailable, exposed, or misused, how many other accounts, files, people, or systems could be affected?
- Many or major consequences: High
- Limited but meaningful consequences: Medium
- Narrow and easily contained consequences: Lower
- I cannot tell: Unknown
Part 1 — Put Your Mac at the Center
Start with the device you are mapping.
Mac name or nickname: _______________________________________________
Who uses this Mac? _________________________________________________
Main uses: Personal / Work / School / Creative / Financial / Development / Shared / Other
My everyday Mac account is: Administrator / Standard user / Unknown
Apple Account signed in: Yes / No / Unknown
This Mac is shared with another person: Yes / No / Sometimes / Unknown
Remote access or sharing is enabled: Yes / No / Unknown
A current backup exists: Yes / No / Unknown
The most important thing this Mac can reach is:
Your three connection rings
Use these rings to visualize reach.
Ring 1 — On or directly attached to the Mac
Local files, browser profiles, saved passwords, apps, extensions, login items, cloud folders in Finder, and macOS permissions.
Ring 2 — Reached through the Mac
Email, cloud accounts, work systems, financial services, social accounts, active browser sessions, and connected applications.
Ring 3 — Wider consequences
Accounts that can be reset, shared folders and people, client or customer systems, administrator access, automated actions, and other services reached through Ring 1 or Ring 2.
The rest of the worksheet fills in these three rings.
Part 2 — Control Accounts
Control accounts can unlock, reset, recover, or approve access to other accounts. Map these first.
| Control point | Account label | How the Mac connects | What it can unlock, reset, or approve | Consequence |
|---|---|---|---|---|
| Primary email | High / Medium / Lower / Unknown | |||
| Password manager | High / Medium / Lower / Unknown | |||
| Apple Account | High / Medium / Lower / Unknown | |||
| Phone carrier or recovery number | High / Medium / Lower / Unknown | |||
| Main Google or Microsoft account | High / Medium / Lower / Unknown | |||
| Other recovery or administrator account | High / Medium / Lower / Unknown |
Control account I should review first: ________________________________
Why: ________________________________________________________________
What I still do not know: ___________________________________________
Part 3 — Browser Profiles, Sessions, and Extensions
Complete one row for every browser profile you use. A “Work” and “Personal” profile in the same browser are two separate rows.
| Browser and profile | Purpose | Signed in or synced? | Passwords or autofill saved? | Important sessions open | Extensions known? | Consequence |
|---|---|---|---|---|---|---|
| Personal / Work / Experimental / Shared | Yes / No / Unknown | |||||
| Personal / Work / Experimental / Shared | Yes / No / Unknown | |||||
| Personal / Work / Experimental / Shared | Yes / No / Unknown | |||||
| Personal / Work / Experimental / Shared | Yes / No / Unknown |
Extensions worth mapping
List extensions that can read or change website data, manage downloads, use the clipboard, block or rewrite content, connect to accounts, or add AI features.
| Extension | Browser/profile | What sites or data can it reach? | Still used and recognized? | Consequence or Unknown |
|---|---|---|---|---|
| Yes / No / Unknown | ||||
| Yes / No / Unknown | ||||
| Yes / No / Unknown | ||||
| Yes / No / Unknown |
Browser profile with the widest reach: _______________________________
Why: ________________________________________________________________
Part 4 — Cloud Storage and Important Files
Cloud storage
Include services visible in Finder and services you use only through a browser.
| Service | Synced to Mac? | Important or sensitive content | Shared folders or links | Connected apps | Consequence |
|---|---|---|---|---|---|
| iCloud Drive | Yes / No / Unknown | ||||
| Google Drive | Yes / No / Unknown | ||||
| Dropbox | Yes / No / Unknown | ||||
| OneDrive | Yes / No / Unknown | ||||
| Other | Yes / No / Unknown |
Important files on the Mac
Mark categories only. Do not record filenames or confidential details.
- Identity documents
- Tax, banking, or accounting records
- Medical or legal documents
- Password exports, recovery codes, or security keys information
- Private photos, messages, or personal records
- Work or client files
- Customer, employee, or student data
- Contracts or business records
- Source code, API credentials, or configuration files
- Other important files: ___________________________________________
- I do not yet know what important files are stored locally
Highest-consequence file category: _________________________________
Where it is stored or synced: ______________________________________
Who else could be affected: ________________________________________
Part 5 — Work, Client, Financial, and Admin Access
Work, client, school, and business systems
Examples: work email, Google Workspace, Microsoft 365, Slack, Teams, Notion, ClickUp, payroll, accounting, customer support, website administration, domain registrar, hosting, ecommerce, advertising, VPN, or remote desktop.
| System label | How the Mac reaches it | Admin or elevated access? | Other people or data affected | Consequence |
|---|---|---|---|---|
| Yes / No / Unknown | ||||
| Yes / No / Unknown | ||||
| Yes / No / Unknown | ||||
| Yes / No / Unknown |
Financial access
Examples: bank, card, payment app, brokerage, crypto exchange, accounting system, Stripe, PayPal, or ecommerce payments.
| Account label | Signed in on Mac? | Password or payment data saved? | Can move money or change payment details? | Consequence |
|---|---|---|---|---|
| Yes / No / Unknown | Yes / No / Unknown | Yes / No / Unknown | ||
| Yes / No / Unknown | Yes / No / Unknown | Yes / No / Unknown | ||
| Yes / No / Unknown | Yes / No / Unknown | Yes / No / Unknown |
Work, client, or financial system I should review first:
Why: ________________________________________________________________
Part 6 — AI Tools, Agents, and Connected Applications
Include:
- AI websites and desktop apps;
- AI browser extensions;
- coding agents, if you use them;
- browser or computer-use agents;
- automations;
- local AI applications;
- connectors or MCP servers, if relevant; and
- applications linked to Google, Microsoft, Slack, Notion, GitHub, cloud storage, or other important accounts.
Connected applications are sometimes described as OAuth connections. They may remain connected even when you are not actively using the app.
| Tool or connection | Type | Accounts, files, browser, or services connected | What can it read? | Can it send, change, delete, publish, buy, or deploy? | Consequence |
|---|---|---|---|---|---|
| AI app / Extension / Agent / Automation / Connected app / Other | Yes / No / Unknown | ||||
| AI app / Extension / Agent / Automation / Connected app / Other | Yes / No / Unknown | ||||
| AI app / Extension / Agent / Automation / Connected app / Other | Yes / No / Unknown | ||||
| AI app / Extension / Agent / Automation / Connected app / Other | Yes / No / Unknown | ||||
| AI app / Extension / Agent / Automation / Connected app / Other | Yes / No / Unknown |
Why the combination matters: A tool that can read untrusted webpages, emails, files, or messages may encounter instructions you did not write. If that same tool can act through connected accounts or broad Mac permissions, the possible consequence is wider. Map both what it can read and what it can do.
Tool or connected app with the widest reach: _________________________
What makes its reach wide: __________________________________________
Unused or forgotten connection found: _______________________________
Part 7 — Powerful Mac Access, Sharing, and Backups
Open System Settings → Privacy & Security. Record apps you recognize as well as anything you need to investigate.
| Access area | App or service found | Why does it need this access? | Recognized and still needed? | Consequence or Unknown |
|---|---|---|---|---|
| Full Disk Access | Yes / No / Unknown | |||
| Accessibility | Yes / No / Unknown | |||
| Input Monitoring | Yes / No / Unknown | |||
| Screen & System Audio Recording | Yes / No / Unknown | |||
| Files & Folders | Yes / No / Unknown | |||
| Automation or App Management | Yes / No / Unknown | |||
| Remote Desktop | Yes / No / Unknown |
Now check System Settings → General → Login Items & Extensions and General → Sharing.
| Connection area | What is enabled or present? | Expected and still needed? | Consequence or Unknown |
|---|---|---|---|
| Open at Login | Yes / No / Unknown | ||
| App Background Activity | Yes / No / Unknown | ||
| Added, Finder, network, or other extensions | Yes / No / Unknown | ||
| Remote Login, Remote Management, Screen Sharing, or File Sharing | Yes / No / Unknown |
Backup check
Backup method: Time Machine / Cloud backup / Other / None / Unknown
Last successful backup I can identify: ______________________________
Important files appear included: Yes / No / Unknown
Backup destination is available if the Mac is lost or unavailable: Yes / No / Unknown
Backup item to review: ______________________________________________
This quick check confirms visibility, not whether a backup is complete, clean, or fully restorable.
Part 8 — Unknown or Forgotten Connections
Unknowns are a result, not a failure. The goal is to turn important unknowns into clear answers.
Look for:
- an old browser or browser profile;
- an extension you no longer recognize or use;
- an app that starts or runs in the background;
- an account linked through “Sign in with Apple,” Google, or Microsoft;
- a connected AI tool, agent, automation, or connector;
- an old shared cloud folder or public link;
- a Mac permission you do not remember granting;
- remote access or sharing you did not intentionally enable;
- a former work, client, school, or contractor account;
- an old device still trusted by an important account; or
- a backup whose date, contents, or location you cannot confirm.
| Unknown | Where I will check | Why it could matter | Review by |
|---|---|---|---|
Unknown attached to the widest-reaching account or permission:
Part 9 — Draw the Reach Chains
The map becomes useful when you connect the dots. Complete every chain that applies. Add more if needed.
Control chain
Mac → __________________ browser or app → __________________ control account → can reset or approve → __________________
Cloud and file chain
Mac → __________________ synced service → __________________ important files or shared folder → affects → __________________
Work or financial chain
Mac → __________________ session or app → __________________ work/admin/financial system → can affect → __________________
AI or connected-app chain
Mac → __________________ AI tool/agent/connected app → can read → __________________ and can act in → __________________
Permission chain
Mac → __________________ app → has permission to access or control → __________________ which could affect → __________________
Widest chain
The connection with the widest consequences is:
Because it could reach, reset, reveal, share, or control:
Part 10 — Build Your First-Review List
Do not try to review everything at once. Pull the most important items from the previous pages.
High consequence — review first
Unknown — resolve early
Medium consequence — review next
Lower consequence — review after the above
Review-order rule
Start with:
- unknowns attached to control accounts, broad permissions, financial access, or work/client/admin systems;
- high-consequence control accounts and browser sessions;
- unused tools, extensions, agents, or connected apps with broad reach;
- important local, cloud, or shared files;
- work, client, or financial connections that affect other people; and
- backup unknowns.
Your Completed Map — Interpretation
There is no winning number and no “safe” result. Look for the pattern your map reveals.
If you found several high-consequence connections
Your Mac is functioning as a major access point to your digital life. That may be completely normal for how you work. The priority is to make that reach intentional: review control accounts, active sessions, connected apps, powerful permissions, and separation between everyday, sensitive, work, and experimental activity.
If you found only a few high-consequence connections but many unknowns
Your biggest gap is visibility. Resolve unknowns attached to email, password management, recovery, browser sync, work/admin access, financial services, AI tools, and broad Mac permissions before spending time on low-consequence items.
If one browser profile reaches almost everything
Your browser is acting as a control room. Signed-in sessions, sync, saved credentials, extensions, and site access are concentrated in one place. Review that profile first and consider separating sensitive, work, everyday, and experimental activity.
If an AI tool or agent can both read and act
Focus on the combination. Identify what content can influence the tool, which accounts and files it can reach, what actions it can take, and where human approval is required. A familiar brand name does not answer those access questions.
If work, client, customer, or financial systems appear on the map
The consequences may extend beyond you. Identify the owner of each system, the access you hold, and any workplace, contractual, insurance, legal, or reporting rules that apply. Do not make unilateral changes to managed systems when another responsible party should be involved.
If your map is short and your answers are mostly known
You may have a more contained and intentional setup. That is useful, but this worksheet still does not verify the condition of the Mac or its accounts. Keep the map current when you add a browser, device, extension, AI tool, agent, connected app, cloud service, or new work responsibility.
If your backup is missing or unknown
Treat backup readiness as a priority. A backup affects how calmly you can respond to device loss, damage, mistakes, or a future rebuild. Confirm what is backed up, where it is stored, and when the last successful backup occurred.
Immediate Next Actions
Do now
- Circle your widest reach chain.
- Choose one high-consequence item and one important unknown to review first.
- Confirm the purpose of any extension, app, agent, connected application, or Mac permission you no longer recognize.
- Remove or revoke access that is clearly unused only after confirming what depends on it and how to reconnect it if needed.
- Confirm the date and location of your latest backup.
- Store this map somewhere private and accessible. It describes the structure of your digital life.
Do this week
- Review recovery details, trusted devices, active sessions, and connected apps for your control accounts.
- Reduce unnecessary browser extensions, account connections, background access, sharing, and powerful Mac permissions.
- Separate experimental tools and unfamiliar downloads from the browser profile or Mac account used for sensitive work where practical.
- Review high-consequence work, client, financial, cloud, and admin systems with the appropriate owner or responsible person.
- Resolve the first three unknowns on your list.
- Put a recurring monthly reminder on your calendar to review new tools, extensions, connections, permissions, and backup status.
Pause before removing something you do not understand. Record its name and where you found it. Check the developer or service through an official source. For a managed work or school Mac, follow the organization’s process.
If something already feels wrong
This map is not an incident-response process. If you are seeing unexpected sign-ins, unauthorized financial activity, account lockouts, unfamiliar remote access, or concern involving employer, client, customer, legal, regulated, or highly sensitive data, move to the HardenMac First-Hour Emergency Sheet and seek appropriate professional or organizational help where needed.
Do not use a completed map as proof that nothing happened.
What This Free Map Does—and What the Full HardenMac System Adds
The free Mac Exposure Map gives you
- a high-level inventory of your major Mac connections;
- a simple consequence classification;
- a view of control accounts, browser reach, cloud and file reach, work and financial access, AI tools, connected apps, permissions, backups, and unknowns;
- a set of connection chains showing how one access point can lead to another; and
- a practical first-review list.
That is real standalone value. You can use the map to remove clearly unnecessary access, resolve important unknowns, confirm backup visibility, and make future tool decisions more intentionally.
The paid HardenMac system adds the operating process
The full system takes the connections you found and gives you the deeper sequence, checklists, trackers, and decision support to reduce exposure, establish a safer baseline, prepare for an incident, and respond if trust is lost.
| What your free map reveals | Continue with this paid HardenMac asset |
|---|---|
| Several high-consequence or interdependent connections | Exposure Map Worksheet for the full preventive and incident-oriented inventory, reach analysis, priorities, actions, and unresolved unknowns |
| One browser profile holds most sessions, credentials, extensions, or account access | Browser Lockdown Checklist |
| AI tools, extensions, agents, automations, connectors, or account links have broad reach | AI Tool & Extension Safety Protocol and AI Tool Permissions Inventory |
| Mac permissions, login items, sharing, updates, accounts, or backups need a safer baseline | Mac Hardening Checklist |
| Control accounts and recovery dependencies need structured preparation | Account Rotation Tracker and the relevant preparation sections of the core playbook |
| Something feels wrong or an active concern already exists | First-Hour Emergency Sheet, then the incident route in the HardenMac Safety & Recovery Protocol |
| You no longer know whether the Mac can be trusted | Clean Rebuild Decision Tree, followed by the Post-Rebuild Setup Checklist when appropriate |
You do not need to buy the full system for this map to be useful. The paid system is most valuable when the map reveals several high-consequence chains, many unresolved unknowns, broad browser or AI access, work/client responsibilities, or a need for an ordered protection and recovery process rather than a one-time inventory.
HardenMac is not antivirus, a scanner, monitoring software, professional incident response, or a guarantee that a Mac is clean. It is a human-led safety, protection, and recovery system for making reach visible, reducing unnecessary exposure, and knowing what to do next.
Final Exposure Statement
Complete this page after finishing the worksheet.
This Mac is mainly connected to:
My three highest-consequence connections are:
The widest connection chain is:
__________________ → __________________ → __________________ → __________________
The three unknowns I will resolve first are:
The first three reviews I will complete are:
Date completed: ____________________
Next monthly review: ____________________
See what your Mac can reach. Reduce the blast radius. Know exactly what to do next.
Official-Source Verification Notice
System Settings labels and paths were checked against current official guidance on August 9, 2026. Apple and account providers may change their menus and terminology. Use the provider’s current official instructions when a label differs.
- Apple: Change Privacy & Security settings on Mac
- Apple: Change Login Items & Extensions settings on Mac
- Apple: Allow a remote computer to access your Mac
- Apple: Time Machine settings on Mac
- Google: Manage links between your Google Account and apps from other developers