# S1 — launchd user domain

Re-surveyed **August 7, 2026** (snapshot 2026-08-08 02:05 UTC; previous pass July 28, 2026 13:00 UTC). Wolf's user-session launchd surface now contains **20 in-scope items**: 13 plist definitions in the two permitted LaunchAgents directories and seven ServiceManagement-submitted registrations with no standalone plist there. The scope deliberately summarizes 450 `com.apple.*` services (an unchanged count) and 14 `application.*` transient GUI registrations (nine last time — simply more GUI apps open at this moment) rather than turning them into S1 records.

## What changed since July 28

**Two additions, no removals.** Nothing was uninstalled or unregistered in the eleven days between surveys.

| Label | What actually happened on the machine |
|-------|----------------------------------------|
| `homebrew.mxcl.ollama` | **Installed as a service.** The plist was created 2026-07-31 03:30 local — `brew services start ollama` was run three days after the last survey, promoting Ollama from a plain formula to a login-armed daemon (RunAtLoad + KeepAlive). It is running now, pid 1163. |
| `com.microsoft.VSCode.ShipIt` | **Registered by an app, not by Wolf.** Visual Studio Code submitted its Squirrel updater helper (`submitted by Code[68807]`) while staging an update in this window. It has run once, exited 0, and sits idle. |

**Every pid in this surface changed, and that is a reboot, not instability.** `kern.boottime` reads Mon Aug 3 05:00:53 2026 — the machine restarted mid-window, so each surviving service came back on a fresh pid (Paragon 890→1165, Chatcode 896→1170, Postgres 893→1168, Redis 884→1159, CleanMyMac 881→1157 / 898→1172, ssh-agent 2659→1612). No label changed kind, trigger, owner, or program path.

The one row where the pid change means something more is `observify.runtimecards.8787` (28721→5645): its `runs` counter reads **16 since a reboot four days ago**, which is its own deploy cycle restarting it under KeepAlive, and its last-exit column is **still `-15`**. That finding is carried forward, not cleared.

Nine in-scope services are running now: Paragon's notification agent, the Chatcode gateway, PostgreSQL 14, Redis, **Ollama**, Observify runtime cards, two CleanMyMac components, and Apple SSH agent. This is a runtime fact, not a claim that Wolf is actively using every one of them; launchd only proves registration and process state. The installed-but-idle group includes XQuartz, Google's updater, five submitted helpers (now including VS Code's ShipIt), and all other registered non-running records. Zoom's two plists, both empty Keystone plists, and Steam's cleaner are defined on disk but have no gui/501 registration at this probe.

## What starts automatically and what is in use

Login-triggered definitions are Paragon's notification agent, Zoom's login check, Steam's cleaner, the Chatcode gateway, PostgreSQL, Redis, Ollama, and Observify runtime cards. Chatcode, PostgreSQL, Redis, Ollama, Observify, and Paragon are running; Steam and Zoom's login check are not registered in the current gui/501 domain. The observed active set therefore shows the live gateway/database/dashboard work plus Paragon notification support, but no inventory can establish whether Wolf is personally using any specific app at this instant.

Scheduled work is GoogleUpdater every hour and ZoomUpdater every hour. Both are currently idle or unregistered. XQuartz, the submitted helpers (including the new VS Code ShipIt registration), and SSH agent are on-demand rather than conventional login work.

## Health, unknowns, and competing work

All current Program/ProgramArguments targets checked in the 13 plist definitions exist — re-verified with `test -e` on every path this survey, including the two new rows — so there is no proven orphaned target. The two empty Keystone-named plists remain the honest unknowns: each parses as an empty dictionary, names no program, and is absent from gui/501. Their names alone are not evidence of what they do.

The one health finding is `observify.runtimecards.8787`: it is running, but launchd's current registry line still reports a prior `-15` exit, unchanged across two surveys and a reboot. It is marked `broken` for investigation, not silently called healthy. No other in-scope registry line showed a nonzero last-exit status — the new ShipIt row exited 0 and the new Ollama row has never exited.

There is no demonstrated active duplicate updater. Zoom's login check and scheduled update are complementary definitions for the same vendor; the empty Keystone stubs are inactive cleanup candidates beside the current Google updater, not proof that multiple Google updaters are running.

The transient-service rule was re-audited across all 20 rows. None is marked transient: each plist-backed item is persistent by definition, and the seven submitted helpers remain in the registry independently of whether their parent app currently has them running. VS Code's ShipIt was deliberately NOT flagged transient — it survived the reboot's new login session and is still registered with `runs = 1`, so its registration persists past the submitting process.

## Security-sensitive items

The persistent Chatcode gateway has a credential-like environment field and an authorized-keys path; its value is intentionally absent from every artifact. PostgreSQL and Redis are persistent database servers, so their listener and authentication settings deserve a separate review before network exposure. Observify is a persistent runtime-card service and has the recurring `-15` exit noted above. **Ollama is newly security-sensitive on this surface**: `ollama serve` now runs from login and holds a long-lived local model-server listener that any local process can drive without authentication — S12 saw its `llama-server` on a rotating loopback port at the same scan. It is loopback-only, but it is a new standing listener that was not armed at login eleven days ago. Apple SSH agent handles local SSH identities. The Paragon agents and Docker helper are also marked for review because they sit beside external-filesystem and container-management capabilities.

## Dispositions

- `com.paragon-software.extfs.notification-agent` — keep if ExtFS is used; investigate its filesystem-access scope before removal.
- `org.xquartz.startx` — prune if Wolf no longer uses XQuartz/X11; otherwise keep on demand.
- `us.zoom.updater.login.check` — keep with Zoom; prune with Zoom if updates are managed elsewhere.
- `us.zoom.updater` — keep with Zoom; prune with Zoom if updates are managed elsewhere.
- `com.google.GoogleUpdater.wake` — keep if Google applications should self-update.
- `com.google.keystone.agent` — investigate, then a safe prune candidate if confirmed retired.
- `com.google.keystone.xpcservice` — investigate, then a safe prune candidate if confirmed retired.
- `com.valvesoftware.steamclean` — keep with Steam; prune if Steam is no longer used.
- `dev.chatcode.gateway` — keep; investigate its credential, SSH-key, and network boundary during a dedicated security review.
- `homebrew.mxcl.postgresql@14` — keep only while local PostgreSQL 14 data/services are needed; investigate listener/authentication before exposure.
- `homebrew.mxcl.redis` — keep only while local Redis is needed; investigate listener/authentication before exposure.
- `homebrew.mxcl.ollama` — **new**; keep if Wolf wants a local model server always available, prune with `brew services stop ollama` if he only wants it on demand (the formula stays installed either way).
- `observify.runtimecards.8787` — investigate the `-15` exit first; keep while Wolf uses the runtime dashboard.
- `com.SMI-Inc.InstantViewHelper` — investigate; prune only by removing/disable its parent app if InstantView is unused.
- `com.paragon-software.extfs.FSMenuAppLoginItemHelper` — keep if ExtFS is used; otherwise prune with the parent app.
- `com.macpaw.CleanMyMac5.Menu` — keep while CleanMyMac is used; prune with the parent app if not.
- `com.docker.helper` — keep with Docker Desktop; otherwise prune with the parent app.
- `com.macpaw.CleanMyMac5.HealthMonitor` — keep while CleanMyMac is used; prune with the parent app if not.
- `com.openssh.ssh-agent` — keep; it is SIP-protected Apple infrastructure for local SSH identity use.
- `com.microsoft.VSCode.ShipIt` — **new**; keep with Visual Studio Code. Booting it out is not durable — VS Code re-submits it the next time it stages an update.

For a leaner login, the top three low-risk candidates remain the two empty Keystone plists, after confirming retirement, and XQuartz startx if X11 is unused. Their documented stop-and-remove recipes are in `inventory.yaml`; none was executed. Removing active Chatcode, PostgreSQL, Redis, Paragon, Observify, or SSH entries would interrupt live workflows or user-session infrastructure.

## Self-use check

- Automatic login work is listed above. The running subset is Paragon notification, Chatcode gateway, PostgreSQL, Redis, Ollama, Observify runtime cards, and the two submitted CleanMyMac components plus SSH agent; launchd cannot prove user intent beyond those runtime facts.
- The nine services running at the probe are exactly: `com.paragon-software.extfs.notification-agent`, `dev.chatcode.gateway`, `homebrew.mxcl.postgresql@14`, `homebrew.mxcl.redis`, `homebrew.mxcl.ollama`, `observify.runtimecards.8787`, `com.macpaw.CleanMyMac5.Menu`, `com.macpaw.CleanMyMac5.HealthMonitor`, and `com.openssh.ssh-agent`. Every other inventory row is idle or unregistered.
- No plist program target was proven missing. The Observify service is the one current broken finding because its registry reports `-15`; the two empty Keystone plists are unresolved unknowns, not asserted failures.
- No competing active updater is demonstrated. Zoom's two definitions have distinct login and scheduled roles; the Keystone stubs are inactive alongside Google's current updater.
- Security-sensitive rows are the two Paragon helpers, Chatcode gateway, PostgreSQL, Redis, Ollama, Observify runtime cards, Docker helper, and SSH agent. The rationale and follow-up scope appear in their inventory notes and in the security section above.
- The top three lean-login candidates are `com.google.keystone.agent`, `com.google.keystone.xpcservice` after confirmation, and `org.xquartz.startx` if X11 is unused. Their documented removal commands are inventory documentation only and were not run.

## Verification gaps, stated honestly

- **Degrade rung: none needed.** Every command this surface's spec declares ran cleanly and unprivileged. No sudo was used, and no mutating `launchctl` verb (bootout/load/unload/kickstart) was run — every `kill` line in `inventory.yaml` is documentation.
- **The two empty Keystone plists remain unknowns.** They still parse as empty dictionaries and name no program, so there is still nothing to inspect. Eleven days did not change that; only Google's own uninstaller or a filesystem archaeology pass would.
- **`dev.chatcode.gateway` holds a credential.** `GATEWAY_AUTH_TOKEN` is present in the plist's `EnvironmentVariables`. Its NAME and PATH are recorded; its value was redacted at read time and never entered any artifact.
- **Registration is not usage.** launchd proves a service is registered and whether a pid exists. It cannot prove Wolf wants any of it. Every disposition above is a suggestion for a human, not a finding.
