Install On Guard · macOS
Steps checked August 17, 2026
Install On Guard on your Mac
Download the disk image, drag On Guard into Applications, and let the setup checklist walk you through the Guard Engine, sign-in, and the two macOS permissions the guard needs. About three minutes.
- Time
- About 3 minutes
- You need
- A Mac running macOS 13 (Ventura) or later.
- Administrator access on the Mac (macOS asks you to approve a background service).
- An email address, or a Google account.
Heads up: Run On Guard from your Applications folder, not from the mounted disk image. Launching it straight from the DMG pins the Guard Engine to a volume that disappears when you eject it.
On this page
Step 1
Get the app
The download is a signed, notarized disk image, so macOS opens it without a security warning.
- Download the macOS build from the downloads page. Opens in a new tab
The file is a disk image (.dmg). Your browser may ask where to save it — the Downloads folder is fine.
Open the DMG and drag On Guard into your Applications folder.
The window says "Drag On Guard into your Applications folder" and shows the Applications shortcut on the right.
Eject the disk image, then open On Guard from Applications (or Spotlight).
First launch needs an internet connection so macOS can confirm the notarization.
Step 2
Run the setup checklist
Three intro panes explain what On Guard does; "Start setup" opens a checklist that completes itself top to bottom. Two rows need you.
Read the intro and tap "Start setup".
"The internet is engineered against you." → "Here's how it works." → "You brought the resolve. Here's the system."
"Started Up" completes on its own.
"On Guard launched and its app services are ready."
Install the Guard Engine
Required"The Guard Engine is an on-device service that powers the anti-algorithm. Your system may ask you to approve a background service. That's the engine."
Tap "Install".
The row shows "Installing…" while macOS registers the engine.
If System Settings opens, switch On Guard on under General → Login Items & Extensions, then come back.
macOS may ask you to allow On Guard to run in the background. If the row times out, it says: "Approve "On Guard" in System Settings → Login Items & Extensions, then retry."
"Connect to Guard Engine" and "Check for Updates" then run by themselves.
Connect ends with "Connected. Contract v…". If macOS asks about Keychain access, that is On Guard storing its secure key — allow it.
If you skip this: Setup cannot finish without the engine — it is what watches the screen. Use "Retry install" after approving it in System Settings.
Sign in to On Guard
RequiredOn "Sign in to On Guard", tap "Sign in".
Your browser opens On Guard's sign-in page; the app waits with "Reopen browser" in case you close it by accident.
Choose "Continue with Google", or enter an email and password and tap "Create an account" (or "Sign in" if you already have one).
One account covers every device you install On Guard on. Sign in with Apple is available on iPhone and iPad, not on desktop.
Return to the app — the checklist finishes with "All Set!" — "You are on guard and ready to go."
Step 3
Turn on the macOS permissions
After "All Set!", the dashboard shows a Permissions card whenever something is off: "On Guard needs these turned on to keep your full defense running." Each row has a "Turn on …" button that opens the right pane. Two rows carry the guard.
Screen Recording
Required"Lets On Guard detect explicit content on your screen." Frames are analyzed on this Mac and never saved or sent anywhere.
On the Permissions card, tap "Turn on Screen Recording".
macOS shows its own prompt the first time. On Guard asks for this after you have activated, not during the checklist.
If no prompt appears, open System Settings → Privacy & Security → Screen Recording and switch On Guard on.
Give it a moment to register.
The grant takes effect when On Guard's capture service restarts, so the row can take a few seconds to flip to "On".
If you skip this: On-screen detection stays off. Site blocking still runs, but nothing watches what is on the screen. macOS never re-shows a denied prompt — the switch in Privacy & Security is the only way back.
Accessibility
Required"Lets On Guard check the site you're on and redirect explicit ones."
On the Permissions card, tap "Turn on Accessibility".
In System Settings → Privacy & Security → Accessibility, switch On Guard on.
If you skip this: On Guard cannot read the address of the page you are on, so site checks and redirects stop.
Browser control (Automation)
RecommendedThe first time On Guard moves your browser off a blocked page, macOS asks whether On Guard may control that browser.
Choose OK when macOS asks to let On Guard control your browser.
The request reads: "On Guard checks the address of the page you're on … and moves you to a safe page when a site is blocked. It reads only the current address — never your history or what's on the page."
Changed your mind later? System Settings → Privacy & Security → Automation → On Guard.
If you skip this: Blocked sites stay blocked; only the friendly redirect to a calmer page is off.
Network Filter
OptionalSome builds include a network filter that "stops known explicit sites at the network level, in every browser." If the Permissions card has no Network Filter row, your build does not include it yet — skip this part.
Tap "Turn on Network Filter", read "Turn on the network filter", and tap Continue.
It checks only the address your Mac is connecting to. It never reads the content of your traffic.
macOS asks twice: switch on "On Guard Network Filter" in Network Extensions, then choose Allow when asked if On Guard can filter network content.
If Settings stops at Login Items & Extensions, open Network Extensions under Extensions.
If you skip this: Site blocking falls back to the Accessibility path with a smaller built-in list.
Start at login
On by defaultNothing to do — On Guard registers itself as a login item so defense comes back after a restart.
The switch is in Settings → About → "Start at login". If macOS wants approval, the row says "Waiting for approval in System Settings → Login Items."
Step 4
Invite an ally
Defense is live. One thing makes it count: someone in your corner.
On the "You're on guard." screen, tap "Invite an ally".
"Go to dashboard" skips it. You can invite allies any time later from Allies in the app.
In "Invite your allies", tap Share or Copy link and text it to the people you want in your corner.
One link works for all of them and stays valid for 7 days. "New link" makes a fresh one and retires the old.
Your ally opens the link, and that's it — they get the check-in texts, never the details.
Step 5
Take the walkthrough and start your trial
On your first dashboard visit, "See how it works first." offers a two-minute walkthrough — "See how it works" or "Maybe later". Then the trial card.
Read the "Your guard is up. Keep it up." card and pick Yearly or Monthly.
The card appears over the dashboard on your first visit, after the walkthrough offer.
Tap "Start 30-day free trial".
You are not charged during the trial. Cancel any time from your store or billing account.
Or skip for now — defense keeps running while you decide.
The dashboard then reads "Not activated": "You skipped activation. Defense is still running while you decide. Start your trial to keep it."
Step 6
Confirm it is working
Open the dashboard: the header should read "On guard" — "Real-time defense is running on this device."
"Off guard" or "Update needed" means something still needs attention; the Permissions card at the top of the dashboard says exactly what.
Check the Permissions card: every row should show "On".
A row marked "Action needed" (red) is required for full defense; "Recommended" (amber) is advisory. Each has a "Turn on …" button that opens the right Settings pane.
Optional: Settings → "Test your guard" → "Open the tests" (on builds that include it).
The Block test fires the real chain on a decoy page and sends the TEST text to your own phone; the Feed test fires the real nudge on a demo feed. Test runs never count toward your history.
Step 7
Updates and uninstall
- Updates are automatic: On Guard checks on launch and every few hours, downloads in the background, and applies when the window is closed. Settings → About shows the version, "Last checked", and "Check for updates now".
- Dragging On Guard to the Trash is not a clean uninstall — the engine registration and permissions stay behind. Use the in-app uninstall.
- Uninstall from inside the app: Settings → Danger zone → "Uninstall On Guard". The sheet shows who will be notified and the exact message they get, then "Send & uninstall" turns defense off, tells your allies, and removes On Guard completely. Your allies knowing is the point.
macOS questions
macOS says the app "cannot be verified" or will not open.
The public download is signed and notarized, so that should not happen online. If you were offline on first launch, connect and open it again; if you downloaded from somewhere other than stayonguard.app, delete it and use the official download.
The checklist is stuck on "Connect to Guard Engine".
Open System Settings → General → Login Items & Extensions and make sure "On Guard" is allowed to run in the background, then tap Retry. If you launched On Guard from the mounted DMG, quit it, eject the image, and open the copy in Applications.
I granted Screen Recording but the row still says "Action needed".
The grant only takes effect on a fresh capture process. Wait a few seconds; if it does not flip, quit and reopen On Guard from Applications.
Do I need Screen Recording if I only want sites blocked?
Site checks and redirects run through the Accessibility permission. Screen Recording is what lets On Guard see explicit content on the screen itself, in any app — that is the guard most people install it for.
Steps checked August 17, 2026 against the shipping app. If a screen no longer matches, email team@stayonguard.app.