This installs PrivacyFence to /Applications and, since it needs an administrator password anyway, also sets it up to run independently of any AI client on this Mac:
_privacyfence system account owns PrivacyFence's data,
settings and audit log — so the AI client PrivacyFence governs can no longer read or
rewrite them.This is the same change described in this project's ADR 0002 and issue #428 — it can
be reversed at any time from Terminal with
sudo /Applications/PrivacyFenceApp.app/Contents/Resources/scripts/macos_privilege_separation.sh disable.