tidy.
Guide

How to protect a folder before you let an AI agent like Claude or Codex work on your Mac

Sebastián Díaz Thomas · Santiago, Chile · September 2026

Short answer: before the agent starts, duplicate the folder in the Finder with ⌘D. On your Mac’s own disk that copy is instant and uses no extra space until files change. Start the agent inside the original folder only, keep sensitive files out of it, and leave its approval prompts on. When it’s done, compare the two folders, and if something went wrong, put the copy back.

That’s the whole idea. The rest of this page is the detail, written for people whose folders are full of PDFs and spreadsheets rather than code.

The situation is familiar by now. You ask an agent to tidy a project folder or rename a batch of invoices. It works fast and sounds sure of itself. When it’s done, you can’t tell what changed. Maybe something is missing, or maybe it was only moved into a subfolder you haven’t opened.

Ask ChatGPT, Gemini or Claude how to guard against this and you tend to get the same three pieces of advice: have a way back, limit what the agent can see, and make it ask before it acts.

1. Have a way back, before you start

This layer matters most. The other two lower the odds of a mistake; this one is what you use when a mistake happens anyway.

Duplicate the folder in the Finder. Select it and press ⌘D. On a Mac’s own disk, which uses APFS, the Finder doesn’t copy the files: it makes a clone, a copy that shares the same data on disk until one side changes. Get Info will show the copy at full size, which is why most people assume it takes double the space. It doesn’t. I duplicated a 500 MB folder this way and the free space on the disk didn’t move; a normal copy of the same folder used 477 MB.

The copy appears next to the original, outside the folder the agent will work in. Keep it there, so the agent doesn’t tidy your safety copy as well.

Three limits. The clone only happens within the same APFS volume: duplicate onto an external drive, or a USB stick formatted as exFAT, and you get a normal copy that takes full space. If your Documents folder syncs with iCloud, the duplicate is uploaded too and counts against your iCloud storage, and files that are only in the cloud should be downloaded first (right-click › Download Now) so the copy holds real files. And a clone is not a backup: both versions live on the same disk and share its data, so a failing drive takes both. For that, press Back Up Now in Time Machine before you start.

If the folder holds code, the programmers’ answer is the right one: commit to Git before the session, and every change can be reviewed and reverted.

Seeing what changed

Open Terminal (⌘Space, type Terminal), type diff -rq followed by a space, drag the copy into the window, drag the original after it, and press Return:

diff -rq "My Project copy" "My Project"

Each line is one difference. Only in …: name means that file exists in only one of the two folders; Files … differ means its content changed. Lines about .DS_Store are the Finder’s own housekeeping, and you can ignore them. The first time, macOS may ask whether Terminal can access your Documents folder.

diff compares names and content, not dates or tags, and it can’t tell a moved file from a deleted one. A file the agent moved into a subfolder shows up as missing in one place and new in another. Working out which is which is up to you.

Going back

If you want a few files back, drag them from the copy. If the whole result is wrong, move the agent’s version to the Trash and rename the copy to the original name. And when you’re happy with the result, delete the copy: it costs nothing while the two are identical, but the more the original changes, the more real space the copy holds.

2. Give the agent a smaller view

An agent can only damage what it can reach. Start it inside the one folder the task needs, never your home folder, your Desktop or all of Documents; in a desktop app, that means choosing that folder when it asks where it can work.

Take out of that folder anything the task doesn’t need: documents with other people’s personal data, exported passwords, files containing API keys. Keeping a secret out of reach is easier than trusting an agent to ignore it.

Be clear about what this buys you. In Codex, the sandbox keeps edits inside the folder. In Claude Code, file edits stay in the folder you started in, but a shell command you approve can reach further. And the app that runs the agent carries its own permissions: check System Settings › Privacy & Security, under both Full Disk Access and Files & Folders, and remove your terminal or code editor from anything it doesn’t need. That narrows what the agent can reach. It doesn’t lock it in.

3. Make it ask before it acts

Claude Code asks before it edits files unless you switch that off. Codex works differently: its Auto mode, which it recommends for folders under version control, reads, edits and runs commands inside the folder without asking, and stops only to go outside it or use the network. If you want Codex to ask first, choose Read Only. Options like Claude Code’s --dangerously-skip-permissions are named that way on purpose; they belong in a throwaway virtual machine, not on the Mac with your documents.

Approval prompts only help if you can read what you’re approving: find . -name '*.tmp' -delete looks harmless if Terminal isn’t your language. And by the twentieth “allow” you’ve stopped reading anyway. That’s why the first layer comes first.

What I built for the part diff can’t do

I make a Mac app called Tidy, and version 2.9 adds the first layer as a button, plus the two things the copy-and-diff method lacks.

You protect a folder from the app, or with a right-click on it in the Finder. Tidy makes the same kind of APFS clone as ⌘D, and it also keeps track of each file’s identity. So afterwards it can tell you in plain words what the agent did: what was moved or renamed and where to, what was deleted and how big it was, what changed and what is new.

And it can undo file by file instead of swapping whole folders. Deleted files return, moved files go back where they were, and anything the agent changed keeps its earlier version alongside, marked “(before)”. What the agent created stays, and nothing current is overwritten, so the good parts of its work survive the undo. When everything looks fine, you release the copy.

I tested it with a real Claude agent, a folder of 25 files and the instruction “clean it up and organise it, delete whatever is left over, don’t ask me”. In 57 seconds it deleted six files with rm, which skips the Trash, and moved or renamed eighteen. Tidy listed each one, and Undo brought all 25 back identical.

The limits are the clone’s limits: it protects folders on your Mac’s own disk, not your whole home folder or an external drive; in iCloud it downloads cloud-only files first; and it isn’t a backup. It doesn’t block the agent or read its conversation either. That is what layers two and three are for.


The app is Tidy: $9 once, no subscription, macOS 14 and up, and your files never leave your Mac. The safety net is a card in the Protect group, or right-click a folder in the Finder → “Tidy: Protect this folder”. Tidy also names scanned documents from what they say and lets you search inside them.

Also worth reading: Why Spotlight can’t find text in scanned PDFs · Tidy and Hazel, side by side · The safety net in the user guide

This article in: English · Español · Deutsch · Français · Português