Overview
Velatir for Desktop needs a small set of operating system permissions to capture and inspect AI traffic on a managed device. Everything is requested at install time, and the list is short on purpose: there is no microphone, camera, location, or full-disk access.Windows
The installer asks for administrator rights once. It uses them to place the files and register the background service. After that, the CLI asks for elevation only for commands that change capture or configuration. Traffic capture and the certificate that goes with it are not part of installation. They are set up later, and only if your organisation has enabled capture and the device’s safety checks pass. A device where capture is never enabled holds no certificate and has no traffic redirected. See How it works. Velatir then runs as a background service that starts automatically, so it keeps working across reboots without anyone needing to launch it. A tray icon shows when it is running.macOS
The installer asks for an administrator password once, the standard macOS installer flow. Velatir captures traffic through an approved macOS system extension. There is no kernel extension and no patching of system frameworks.System extension approval
System extension approval
On first run, macOS asks the user to approve Velatir’s network extension in System Settings → General → Login Items & Extensions → Network Extensions. Until it is approved, capture cannot start. On managed Macs you can pre-approve it so there is no prompt; see Enterprise deployment. The extension grants no access to files, user data, or any other system resource.
Certificate
Certificate
Velatir trusts its per-device certificate in the macOS System keychain, so browsers and apps inspect correctly. Some runtimes keep their own trust store; see Troubleshooting. To use your own certificate authority instead, see Bring your own certificate.
Background items and notifications
Background items and notifications
Velatir runs as a background service, so macOS 13 and later tells the user it “added items that can run in the background” and offers to switch them off. Separately, macOS holds notifications from a newly installed app back until the user opts in, which can stop blocked-request alerts reaching anyone. On managed Macs, two configuration profiles settle both before the user sees either. See macOS notification profiles.
Next steps
VPN compatibility
How Velatir works alongside corporate VPNs.
Enterprise deployment
Silent install, bring-your-own CA, and MDM rollouts.
Data privacy
What Velatir stores, and how you choose storage and retention.
Troubleshooting
Diagnose certificate and approval issues.