| name | apple-notes-enterprise-rbac |
| description | Implement access control for multi-user Apple Notes automation.
Trigger: "apple notes access control".
|
| allowed-tools | Read, Write, Edit, Bash(osascript:*), Grep |
| version | 1.6.0 |
| license | MIT |
| author | Jeremy Longshore <jeremy@intentsolutions.io> |
| tags | ["saas","macos","apple-notes","automation"] |
| compatibility | Designed for Claude Code |
Apple Notes Enterprise RBAC
Overview
Apple Notes has no built-in role-based access control (RBAC). In enterprise environments with Managed Apple IDs via Apple Business Manager, administrators control Notes access through MDM (Mobile Device Management) profiles. For multi-user automation scenarios, implement access control at the automation layer using account separation, folder-based permissions, and shared folder restrictions. iCloud Shared Notes (macOS Ventura+) provide basic collaboration, but fine-grained permissions (read-only vs edit) must be enforced in your wrapper code.
Account-Based Access Control
const Notes = Application("Notes");
function getAccountByName(name) {
const account = Notes.accounts().find(a => a.name() === name);
if (!account) throw new Error(`Account not found: ${name}`);
return account;
}
function auditAccounts() {
return Notes.accounts().map(a => ({
name: a.name(),
folders: a.folders().map(f => f.name()),
noteCount: a.notes().length,
}));
}
const ALLOWED_ACCOUNT = "iCloud";
function safeGetNotes() {
account = ();
account.();
}
Folder-Based Permission Model
interface FolderPermission {
folder: string;
allowedRoles: string[];
operations: ("read" | "write" | "delete")[];
}
const FOLDER_PERMISSIONS: FolderPermission[] = [
{ folder: "Public", allowedRoles: ["viewer", "editor", "admin"], operations: ["read"] },
{ folder: "Team", allowedRoles: ["editor", "admin"], operations: ["read", "write"] },
{ folder: "Sensitive", allowedRoles: ["admin"], operations: ["read", "write", "delete"] },
];
function checkPermission(role: string, folder: string, op: "read" | "write" | "delete"): boolean {
const perm = FOLDER_PERMISSIONS.find( p. === folder);
(!perm) ;
perm..(role) && perm..(op);
}
MDM-Based Enforcement
profiles status -type enrollment 2>/dev/null
profiles list -verbose 2>/dev/null | grep -A5 "com.apple.notes"
Shared Folder Audit
const Notes = Application("Notes");
const allNotes = Notes.defaultAccount.notes();
const sharedFolders = Notes.defaultAccount.folders()
.filter(f => f.name().toLowerCase().includes("shared"));
sharedFolders.forEach(f => {
console.log(`Shared folder: ${f.name()} — ${f.notes().length} notes`);
});
Error Handling
| Issue | Cause | Solution |
|---|
| Cannot access Managed Apple ID notes | Personal automation on corporate device | Use the managed account explicitly via getAccountByName() |
| Shared folder not visible | iCloud sharing not accepted by recipient | Recipient must accept share invitation in Notes.app |
| MDM blocks osascript | Device restriction profile active | Request IT to allow automation; use Shortcuts as alternative |
| Folder permissions bypass | JXA has full access once TCC approved | Enforce permissions in your wrapper code, not at OS level |
| Multiple accounts create confusion | Notes from wrong account modified | Always specify account explicitly; never use defaultAccount in multi-user |
Resources
Next Steps
For multi-account environment configuration, see apple-notes-multi-env-setup. For security hardening, see apple-notes-security-basics.