This installs PrivacyFence to /Applications and, since it needs an administrator password anyway, also sets it up to run independently of any AI client on this Mac:
_privacyfence system account owns PrivacyFence's data,
settings and audit log — so the AI client PrivacyFence governs can no longer read or
rewrite them.This is the change described in this project's ADR 0002 and issue #428. To uninstall
PrivacyFence later, run this from Terminal — your data is kept unless you add
--purge:
sudo /Applications/PrivacyFenceApp.app/Contents/Resources/scripts/macos_privilege_separation.sh uninstall.