HardenMac Free Mac Exposure Map

Free · No email · Nothing to install

HardenMac — Mac Exposure Map

See what your Mac can reach. Decide what to review first.

Free Edition — Version 1.0
Checked: August 9, 2026

Your Mac may be connected to far more than the files stored on it. A browser profile can keep you signed in to email, cloud drives, financial accounts, work systems, and admin tools. An extension or AI tool may be able to read pages, reach local files, use a connected account, or take actions you approve. One control account may be able to reset several others.

The purpose of this worksheet is to make those connections visible.

If you just completed the Mac Exposure Check, this worksheet turns your answers into a practical map. If you started here, it also works on its own.

When you finish, you will know:

This is an exposure-mapping worksheet, not a security scan. It cannot tell you whether your Mac is safe, infected, monitored, or compromised. It does not prove that anyone or anything accessed your information.

Privacy note: Do not write passwords, passkeys, recovery codes, full financial account numbers, API keys, private client information, or other secrets in this worksheet. Use labels such as “primary email,” “main bank,” or “Client A portal.”


How to Complete Your Map

Allow about 20–30 minutes for a first pass. You do not need to know every answer.

1. Begin with what you remember

List the accounts, profiles, services, files, tools, and permissions that come to mind immediately. Do not stop to investigate every item yet.

2. Check the places where connections hide

Look at:

Menu names can vary by macOS version. If a setting has moved, search for its name inside System Settings.

3. Map the connection, not every detail

For each item, record:

  1. What is it?
  2. How does the Mac reach it?
  3. What could it reach, reveal, reset, share, or control?
  4. What consequence level fits?
  5. Is anything still unknown?

4. Use these connection labels

Choose every label that applies.

Label Meaning
On Mac The app, file, credential, or data is stored locally.
Signed in A browser or app has an active account session.
Synced Files, passwords, messages, photos, or settings move between the Mac and a cloud service.
Connected An app or service has been linked to another account, sometimes through “Sign in with…” or OAuth.
Permitted An app has macOS or browser permission to read, observe, or control something.
Can act A tool, automation, or agent can send, edit, delete, publish, purchase, deploy, or perform another action.
Can recover The account, device, email address, or phone number can reset or recover another account.
Unknown You cannot yet confirm the connection, permission, session, owner, purpose, or reach.

5. Classify by consequence, not by fear

This map does not calculate a scientific security score. Use the consequence labels below to create a sensible review order.


Consequence Classification

High consequence

Use High consequence when an item could do one or more of the following if its access were misused:

Common examples include a primary email account, password manager, Apple Account, business administrator account, main financial account, or an AI agent connected to important systems with action permissions.

Medium consequence

Use Medium consequence when an item contains meaningful private information or ongoing access, but does not appear to control a wider part of your digital life.

Examples may include a personal cloud folder, a messaging account, a browser profile with ordinary sessions, a social account, or a tool with access to a limited set of files.

Lower consequence

Use Lower consequence when the connection is narrow, replaceable, and does not appear to contain sensitive information, active privileged access, or a path into more important systems.

Lower consequence does not mean “safe forever.” It means “review after the items with wider effects.”

Unknown

Use Unknown whenever you cannot confidently answer what an item is, why it is present, what it can access, whether it is still connected, or who depends on it.

Unknown does not automatically mean high consequence. It does mean the item is unresolved. Review unknowns connected to control accounts, broad permissions, work/client systems, financial access, or tools that can act before you spend time on known lower-consequence items.

Quick classification test

Ask:

If this one connection were unavailable, exposed, or misused, how many other accounts, files, people, or systems could be affected?


Part 1 — Put Your Mac at the Center

Start with the device you are mapping.

Mac name or nickname: _______________________________________________

Who uses this Mac? _________________________________________________

Main uses: Personal / Work / School / Creative / Financial / Development / Shared / Other

My everyday Mac account is: Administrator / Standard user / Unknown

Apple Account signed in: Yes / No / Unknown

This Mac is shared with another person: Yes / No / Sometimes / Unknown

Remote access or sharing is enabled: Yes / No / Unknown

A current backup exists: Yes / No / Unknown

The most important thing this Mac can reach is:


Your three connection rings

Use these rings to visualize reach.

Ring 1 — On or directly attached to the Mac

Local files, browser profiles, saved passwords, apps, extensions, login items, cloud folders in Finder, and macOS permissions.

Ring 2 — Reached through the Mac

Email, cloud accounts, work systems, financial services, social accounts, active browser sessions, and connected applications.

Ring 3 — Wider consequences

Accounts that can be reset, shared folders and people, client or customer systems, administrator access, automated actions, and other services reached through Ring 1 or Ring 2.

The rest of the worksheet fills in these three rings.


Part 2 — Control Accounts

Control accounts can unlock, reset, recover, or approve access to other accounts. Map these first.

Control point Account label How the Mac connects What it can unlock, reset, or approve Consequence
Primary email High / Medium / Lower / Unknown
Password manager High / Medium / Lower / Unknown
Apple Account High / Medium / Lower / Unknown
Phone carrier or recovery number High / Medium / Lower / Unknown
Main Google or Microsoft account High / Medium / Lower / Unknown
Other recovery or administrator account High / Medium / Lower / Unknown

Control account I should review first: ________________________________

Why: ________________________________________________________________

What I still do not know: ___________________________________________


Part 3 — Browser Profiles, Sessions, and Extensions

Complete one row for every browser profile you use. A “Work” and “Personal” profile in the same browser are two separate rows.

Browser and profile Purpose Signed in or synced? Passwords or autofill saved? Important sessions open Extensions known? Consequence
Personal / Work / Experimental / Shared Yes / No / Unknown
Personal / Work / Experimental / Shared Yes / No / Unknown
Personal / Work / Experimental / Shared Yes / No / Unknown
Personal / Work / Experimental / Shared Yes / No / Unknown

Extensions worth mapping

List extensions that can read or change website data, manage downloads, use the clipboard, block or rewrite content, connect to accounts, or add AI features.

Extension Browser/profile What sites or data can it reach? Still used and recognized? Consequence or Unknown
Yes / No / Unknown
Yes / No / Unknown
Yes / No / Unknown
Yes / No / Unknown

Browser profile with the widest reach: _______________________________

Why: ________________________________________________________________


Part 4 — Cloud Storage and Important Files

Cloud storage

Include services visible in Finder and services you use only through a browser.

Service Synced to Mac? Important or sensitive content Shared folders or links Connected apps Consequence
iCloud Drive Yes / No / Unknown
Google Drive Yes / No / Unknown
Dropbox Yes / No / Unknown
OneDrive Yes / No / Unknown
Other Yes / No / Unknown

Important files on the Mac

Mark categories only. Do not record filenames or confidential details.

Highest-consequence file category: _________________________________

Where it is stored or synced: ______________________________________

Who else could be affected: ________________________________________


Part 5 — Work, Client, Financial, and Admin Access

Work, client, school, and business systems

Examples: work email, Google Workspace, Microsoft 365, Slack, Teams, Notion, ClickUp, payroll, accounting, customer support, website administration, domain registrar, hosting, ecommerce, advertising, VPN, or remote desktop.

System label How the Mac reaches it Admin or elevated access? Other people or data affected Consequence
Yes / No / Unknown
Yes / No / Unknown
Yes / No / Unknown
Yes / No / Unknown

Financial access

Examples: bank, card, payment app, brokerage, crypto exchange, accounting system, Stripe, PayPal, or ecommerce payments.

Account label Signed in on Mac? Password or payment data saved? Can move money or change payment details? Consequence
Yes / No / Unknown Yes / No / Unknown Yes / No / Unknown
Yes / No / Unknown Yes / No / Unknown Yes / No / Unknown
Yes / No / Unknown Yes / No / Unknown Yes / No / Unknown

Work, client, or financial system I should review first:


Why: ________________________________________________________________


Part 6 — AI Tools, Agents, and Connected Applications

Include:

Connected applications are sometimes described as OAuth connections. They may remain connected even when you are not actively using the app.

Tool or connection Type Accounts, files, browser, or services connected What can it read? Can it send, change, delete, publish, buy, or deploy? Consequence
AI app / Extension / Agent / Automation / Connected app / Other Yes / No / Unknown
AI app / Extension / Agent / Automation / Connected app / Other Yes / No / Unknown
AI app / Extension / Agent / Automation / Connected app / Other Yes / No / Unknown
AI app / Extension / Agent / Automation / Connected app / Other Yes / No / Unknown
AI app / Extension / Agent / Automation / Connected app / Other Yes / No / Unknown

Why the combination matters: A tool that can read untrusted webpages, emails, files, or messages may encounter instructions you did not write. If that same tool can act through connected accounts or broad Mac permissions, the possible consequence is wider. Map both what it can read and what it can do.

Tool or connected app with the widest reach: _________________________

What makes its reach wide: __________________________________________

Unused or forgotten connection found: _______________________________


Part 7 — Powerful Mac Access, Sharing, and Backups

Open System Settings → Privacy & Security. Record apps you recognize as well as anything you need to investigate.

Access area App or service found Why does it need this access? Recognized and still needed? Consequence or Unknown
Full Disk Access Yes / No / Unknown
Accessibility Yes / No / Unknown
Input Monitoring Yes / No / Unknown
Screen & System Audio Recording Yes / No / Unknown
Files & Folders Yes / No / Unknown
Automation or App Management Yes / No / Unknown
Remote Desktop Yes / No / Unknown

Now check System Settings → General → Login Items & Extensions and General → Sharing.

Connection area What is enabled or present? Expected and still needed? Consequence or Unknown
Open at Login Yes / No / Unknown
App Background Activity Yes / No / Unknown
Added, Finder, network, or other extensions Yes / No / Unknown
Remote Login, Remote Management, Screen Sharing, or File Sharing Yes / No / Unknown

Backup check

Backup method: Time Machine / Cloud backup / Other / None / Unknown

Last successful backup I can identify: ______________________________

Important files appear included: Yes / No / Unknown

Backup destination is available if the Mac is lost or unavailable: Yes / No / Unknown

Backup item to review: ______________________________________________

This quick check confirms visibility, not whether a backup is complete, clean, or fully restorable.


Part 8 — Unknown or Forgotten Connections

Unknowns are a result, not a failure. The goal is to turn important unknowns into clear answers.

Look for:

Unknown Where I will check Why it could matter Review by

Unknown attached to the widest-reaching account or permission:



Part 9 — Draw the Reach Chains

The map becomes useful when you connect the dots. Complete every chain that applies. Add more if needed.

Control chain

Mac → __________________ browser or app → __________________ control account → can reset or approve → __________________

Cloud and file chain

Mac → __________________ synced service → __________________ important files or shared folder → affects → __________________

Work or financial chain

Mac → __________________ session or app → __________________ work/admin/financial system → can affect → __________________

AI or connected-app chain

Mac → __________________ AI tool/agent/connected app → can read → __________________ and can act in → __________________

Permission chain

Mac → __________________ app → has permission to access or control → __________________ which could affect → __________________

Widest chain

The connection with the widest consequences is:


Because it could reach, reset, reveal, share, or control:



Part 10 — Build Your First-Review List

Do not try to review everything at once. Pull the most important items from the previous pages.

High consequence — review first






Unknown — resolve early






Medium consequence — review next




Lower consequence — review after the above




Review-order rule

Start with:

  1. unknowns attached to control accounts, broad permissions, financial access, or work/client/admin systems;
  2. high-consequence control accounts and browser sessions;
  3. unused tools, extensions, agents, or connected apps with broad reach;
  4. important local, cloud, or shared files;
  5. work, client, or financial connections that affect other people; and
  6. backup unknowns.

Your Completed Map — Interpretation

There is no winning number and no “safe” result. Look for the pattern your map reveals.

If you found several high-consequence connections

Your Mac is functioning as a major access point to your digital life. That may be completely normal for how you work. The priority is to make that reach intentional: review control accounts, active sessions, connected apps, powerful permissions, and separation between everyday, sensitive, work, and experimental activity.

If you found only a few high-consequence connections but many unknowns

Your biggest gap is visibility. Resolve unknowns attached to email, password management, recovery, browser sync, work/admin access, financial services, AI tools, and broad Mac permissions before spending time on low-consequence items.

If one browser profile reaches almost everything

Your browser is acting as a control room. Signed-in sessions, sync, saved credentials, extensions, and site access are concentrated in one place. Review that profile first and consider separating sensitive, work, everyday, and experimental activity.

If an AI tool or agent can both read and act

Focus on the combination. Identify what content can influence the tool, which accounts and files it can reach, what actions it can take, and where human approval is required. A familiar brand name does not answer those access questions.

If work, client, customer, or financial systems appear on the map

The consequences may extend beyond you. Identify the owner of each system, the access you hold, and any workplace, contractual, insurance, legal, or reporting rules that apply. Do not make unilateral changes to managed systems when another responsible party should be involved.

If your map is short and your answers are mostly known

You may have a more contained and intentional setup. That is useful, but this worksheet still does not verify the condition of the Mac or its accounts. Keep the map current when you add a browser, device, extension, AI tool, agent, connected app, cloud service, or new work responsibility.

If your backup is missing or unknown

Treat backup readiness as a priority. A backup affects how calmly you can respond to device loss, damage, mistakes, or a future rebuild. Confirm what is backed up, where it is stored, and when the last successful backup occurred.


Immediate Next Actions

Do now

Do this week

Pause before removing something you do not understand. Record its name and where you found it. Check the developer or service through an official source. For a managed work or school Mac, follow the organization’s process.

If something already feels wrong

This map is not an incident-response process. If you are seeing unexpected sign-ins, unauthorized financial activity, account lockouts, unfamiliar remote access, or concern involving employer, client, customer, legal, regulated, or highly sensitive data, move to the HardenMac First-Hour Emergency Sheet and seek appropriate professional or organizational help where needed.

Do not use a completed map as proof that nothing happened.


What This Free Map Does—and What the Full HardenMac System Adds

The free Mac Exposure Map gives you

That is real standalone value. You can use the map to remove clearly unnecessary access, resolve important unknowns, confirm backup visibility, and make future tool decisions more intentionally.

The paid HardenMac system adds the operating process

The full system takes the connections you found and gives you the deeper sequence, checklists, trackers, and decision support to reduce exposure, establish a safer baseline, prepare for an incident, and respond if trust is lost.

What your free map reveals Continue with this paid HardenMac asset
Several high-consequence or interdependent connections Exposure Map Worksheet for the full preventive and incident-oriented inventory, reach analysis, priorities, actions, and unresolved unknowns
One browser profile holds most sessions, credentials, extensions, or account access Browser Lockdown Checklist
AI tools, extensions, agents, automations, connectors, or account links have broad reach AI Tool & Extension Safety Protocol and AI Tool Permissions Inventory
Mac permissions, login items, sharing, updates, accounts, or backups need a safer baseline Mac Hardening Checklist
Control accounts and recovery dependencies need structured preparation Account Rotation Tracker and the relevant preparation sections of the core playbook
Something feels wrong or an active concern already exists First-Hour Emergency Sheet, then the incident route in the HardenMac Safety & Recovery Protocol
You no longer know whether the Mac can be trusted Clean Rebuild Decision Tree, followed by the Post-Rebuild Setup Checklist when appropriate

You do not need to buy the full system for this map to be useful. The paid system is most valuable when the map reveals several high-consequence chains, many unresolved unknowns, broad browser or AI access, work/client responsibilities, or a need for an ordered protection and recovery process rather than a one-time inventory.

HardenMac is not antivirus, a scanner, monitoring software, professional incident response, or a guarantee that a Mac is clean. It is a human-led safety, protection, and recovery system for making reach visible, reducing unnecessary exposure, and knowing what to do next.


Final Exposure Statement

Complete this page after finishing the worksheet.

This Mac is mainly connected to:


My three highest-consequence connections are:




The widest connection chain is:

__________________ → __________________ → __________________ → __________________

The three unknowns I will resolve first are:




The first three reviews I will complete are:




Date completed: ____________________

Next monthly review: ____________________

See what your Mac can reach. Reduce the blast radius. Know exactly what to do next.


Official-Source Verification Notice

System Settings labels and paths were checked against current official guidance on August 9, 2026. Apple and account providers may change their menus and terminology. Use the provider’s current official instructions when a label differs.


HardenMac is experience-based guidance, not professional advice, and not antivirus or incident response. It does not scan this Mac, its accounts, files or network, and it cannot detect or rule out a problem. Menu names vary by macOS version; if a setting has moved, search for its name inside System Settings.