# S3 — Background Task Management / Login Items

## Surface story

The staged unprivileged sfltool dumpbtm capture contains 96 records: 21 under UID -2, 10 under UID 0, and 65 under UID 501. This unit itemizes all 53 UID-501 non-developer records and summarizes the 12 developer placeholder nodes plus UID -2/UID 0. The capture is primary evidence because the detached worker still receives an authorization failure from sfltool dumpbtm; launchctl print gui/501 was available for agent liveness.

BTM shows 47 records without the not-notified flag and 6 marked not notified: 2.com.openai.chat, 2.com.macpaw.CleanMyMac5, 4.com.macpaw.CleanMyMac5.HealthMonitor, 2.com.docker.docker, 2.com.paragon-software.extfs.fsapp, 2.com.SMI-Inc.InstantView. Three records are explicitly disallowed: 8.com.openai.chat-helper, 8.us.zoom.updater.login.check, 8.us.zoom.updater. Disposition is approval/notification state, not proof of current execution.

The five background agents confirmed in the runtime registry were 8.dev.chatcode.gateway, 8.homebrew.mxcl.postgresql@14, 8.homebrew.mxcl.redis, 8.com.paragon-software.extfs.notification-agent, 8.observify.runtimecards.8787. Historical Last Use timestamps in the capture were not used as liveness evidence.

The referenced /Users/wolf/Library/LaunchAgents/dev.chatcode.gateway.plist contains a credential-bearing environment variable. Its row is marked contains_secrets: true; the value and any prefix are absent from both artifacts.

## Dispositions

Every in-scope item has one disposition. Keep means retain pending Wolf’s own need; investigate means verify before changing; prune means the first candidate for an intentional cleanup pass. No kill field command was executed.

| BTM label | disposition | reason |
|---|---|---|
| 8.tech.thewolf.docker-cache-prune | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 8.dev.chatcode.gateway | **keep** | approved and purpose-bearing; retain while needed and review security exposure |
| 8.homebrew.mxcl.postgresql@14 | **keep** | approved and purpose-bearing; retain while needed and review security exposure |
| 8.homebrew.mxcl.redis | **keep** | approved and purpose-bearing; retain while needed and review security exposure |
| 2.edu.ucsd.cs.mmccrack.bibdesk | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 64.net.sourceforge.bibdesk.bibimporter | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.com.openai.chat | **investigate** | registered without a notification record; confirm Wolf still wants it |
| 8.com.openai.chat-helper | **prune** | blocked or redundant login helper; exact documented path is in inventory.yaml |
| 2.com.macpaw.CleanMyMac5 | **investigate** | registered without a notification record; confirm Wolf still wants it |
| 4.com.macpaw.CleanMyMac5.HealthMonitor | **prune** | blocked or redundant login helper; exact documented path is in inventory.yaml |
| 4.com.macpaw.CleanMyMac5.Menu | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.com.openai.codex | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 128.com.openai.codex.dock-tile-plugin | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.com.docker.docker | **investigate** | registered without a notification record; confirm Wolf still wants it |
| 4.com.docker.helper | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.com.figma.agent | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 8.com.google.GoogleUpdater.wake | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.com.apple.IconComposer | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2048.com.apple.IconComposerQuickLookPreviewAppExtension | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2048.com.apple.IconComposerThumbnailExtension | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.com.apple.logic10 | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2048.com.apple.logic10.LogicProQuickLookExtension | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2048.com.apple.logic10.LogicProThumbnailExtension | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 64.com.apple.MDImporter.LogicX | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.app.markchart.markchart | **investigate** | Team ID is present but codesign did not identify the vendor |
| 2048.app.markchart.markchart.MarkChartQuickLook | **investigate** | Team ID is present but codesign did not identify the vendor |
| 2.com.nordvpn.macos | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 8.com.paragon-software.extfs.notification-agent | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.com.literatureandlatte.scrivener3 | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2048.com.literatureandlatte.scrivener3.ScrivQuickLook | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2048.com.literatureandlatte.scrivener3.ScrivThumbnail | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 64.com.literatureandlatte.scrivener3.ScrivenerMetaDataImporter | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 8.com.valvesoftware.steamclean | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.com.googlecode.mactlmgr.tlu | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 64.com.mac.amaxwell.dviimporter | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.TeXShop | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 64.org.tug.texmdimporter | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.org.m0k.transmission | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2048.org.m0k.transmission.QuickLookExtension | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 8.org.xquartz.startx | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.com.apple.dt.Xcode | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2048.com.apple.dt.DVTProvisioningProfileQuicklookExtension | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 64.com.apple.dt.MDImporter.uuid-importer | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 8.dev.chatcode.maintenance | **keep** | approved and purpose-bearing; retain while needed and review security exposure |
| 2.com.paragon-software.extfs.fsapp | **investigate** | registered without a notification record; confirm Wolf still wants it |
| 4.com.paragon-software.extfs.FSMenuAppLoginItemHelper | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 2.com.SMI-Inc.InstantView | **investigate** | registered without a notification record; confirm Wolf still wants it |
| 4.com.SMI-Inc.InstantViewHelper | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 8.observify.runtimecards.8787 | **keep** | approved and purpose-bearing; retain while needed and review security exposure |
| 2.us.zoom.xos | **keep** | approved/notified record with a defined parent, path, or subsystem role |
| 8.us.zoom.updater.login.check | **prune** | blocked or redundant login helper; exact documented path is in inventory.yaml |
| 8.us.zoom.updater | **prune** | blocked or redundant login helper; exact documented path is in inventory.yaml |
| 8.observify.watchdog | **keep** | approved and purpose-bearing; retain while needed and review security exposure |

## Dossier questions

### Notification and silent registration
The inventory distinguishes 47 records without the not-notified flag from 6 explicitly marked not notified: 2.com.openai.chat, 2.com.macpaw.CleanMyMac5, 4.com.macpaw.CleanMyMac5.HealthMonitor, 2.com.docker.docker, 2.com.paragon-software.extfs.fsapp, 2.com.SMI-Inc.InstantView. The artifact does not infer why those six were not notified.

### Disallowed items
Three records are disallowed: 8.com.openai.chat-helper, 8.us.zoom.updater.login.check, and 8.us.zoom.updater. Their agent live_now values are false, and the ChatGPT helper has no standalone plist. If Wolf expected either app helper/updater to run, investigate the approval state; each exact disable/removal path is in its inventory row.

### App-embedded items and parent-app use
There are 40 application-owned or app-embedded records that do not appear as standalone S1/S2 launchd rows: 2.edu.ucsd.cs.mmccrack.bibdesk, 64.net.sourceforge.bibdesk.bibimporter, 2.com.openai.chat, 2.com.macpaw.CleanMyMac5, 4.com.macpaw.CleanMyMac5.HealthMonitor, 4.com.macpaw.CleanMyMac5.Menu, 2.com.openai.codex, 128.com.openai.codex.dock-tile-plugin, 2.com.docker.docker, 4.com.docker.helper, 2.com.figma.agent, 2.com.apple.IconComposer, 2048.com.apple.IconComposerQuickLookPreviewAppExtension, 2048.com.apple.IconComposerThumbnailExtension, 2.com.apple.logic10, 2048.com.apple.logic10.LogicProQuickLookExtension, 2048.com.apple.logic10.LogicProThumbnailExtension, 64.com.apple.MDImporter.LogicX, 2.app.markchart.markchart, 2048.app.markchart.markchart.MarkChartQuickLook, 2.com.nordvpn.macos, 2.com.literatureandlatte.scrivener3, 2048.com.literatureandlatte.scrivener3.ScrivQuickLook, 2048.com.literatureandlatte.scrivener3.ScrivThumbnail, 64.com.literatureandlatte.scrivener3.ScrivenerMetaDataImporter, 2.com.googlecode.mactlmgr.tlu, 64.com.mac.amaxwell.dviimporter, 2.TeXShop, 64.org.tug.texmdimporter, 2.org.m0k.transmission, 2048.org.m0k.transmission.QuickLookExtension, 2.com.apple.dt.Xcode, 2048.com.apple.dt.DVTProvisioningProfileQuicklookExtension, 64.com.apple.dt.MDImporter.uuid-importer, 2.com.paragon-software.extfs.fsapp, 4.com.paragon-software.extfs.FSMenuAppLoginItemHelper, 2.com.SMI-Inc.InstantView, 4.com.SMI-Inc.InstantViewHelper, 2.us.zoom.xos, 8.com.openai.chat-helper. Parent identifiers are recorded per row. The BTM capture has a Last Use field only for the NordVPN app among these parent-app records (2.com.nordvpn.macos, 2026-07-24 23:05:30-04:00); use of other parent apps is not determinable from this surface.

### Correspondence with S1 and S2
The 13 standalone BTM agent records with LaunchAgents URLs correspond to existing S1/S2 labels after removing BTM’s numeric 8. prefix: S1 owns tech.thewolf.docker-cache-prune, dev.chatcode.gateway, homebrew.mxcl.postgresql@14, homebrew.mxcl.redis, com.google.GoogleUpdater.wake, com.valvesoftware.steamclean, dev.chatcode.maintenance, observify.runtimecards.8787, and observify.watchdog; S2 owns com.paragon-software.extfs.notification-agent, org.xquartz.startx, us.zoom.updater.login.check, and us.zoom.updater. BTM agrees on names, paths, vendors, and purposes and adds approval/notification state. App-embedded login items also match S1 registered-service rows for CleanMyMac, DockerHelper, Paragon FSMenuAppLoginItemHelper, and InstantViewHelper.

### Unknown Developer concern
The strict unknown-developer condition is zero: every null Developer Name record either has a Team Identifier or is resolved by its known Wolf project path/bare interpreter rule. Two MarkChart rows remain honest unknown flags because codesign confirms Team QFL3YR6JR6 and Apple application signing but does not reveal a developer name. That is a vendor-attribution gap, not evidence of malicious behavior; investigate before pruning.

### Lean-startup pass and revoke paths
Start with the four prune dispositions: CleanMyMac Health Monitor uses the documented System Events login-item command in its inventory row; the ChatGPT helper has no standalone removal and is disabled through System Settings > General > Login Items & Extensions or by uninstalling ChatGPT; each Zoom updater has a documented launchctl bootout plus plist removal path. These commands are documentation only. Review the six security-sensitive approved agents after confirming Wolf’s need rather than blindly removing them.

### UID -2 / UID 0 versus S2
The summarized BTM counts are UID -2 = 21 and UID 0 = 10, for 31 total; UID -2 contains 11 legacy-daemon records plus 10 developer placeholders, while UID 0 contains 10 developer placeholders only. S2 has 16 system-scope items. The counts therefore do not match one-for-one: BTM includes developer grouping nodes and approval-layer records, while S2 owns daemon registry detail. The capture demonstrates overlap because 16.com.paragon-software.extfs.loader maps to S2’s com.paragon-software.extfs.loader.

## Evidence and limitations

- Primary source: /Users/wolf/Projects/mac-atlas/captures/btm.txt, 1,313 lines, captured unprivileged at 2026-07-25T05:53:34Z.
- Each inventory row embeds the exact UID-501 BTM block and relevant bounded cross-reference result.
- No sudo, System UI, Automation grant, service mutation, kill command, or configuration write was performed.
- The worker-side sfltool dumpbtm probe is authorization-blocked; the staged capture is the documented coverage basis. The capture-first parity and liveness probes passed against that same staged source, with the bounded launchctl registry supplying the five live-agent matches.

