> For the complete documentation index, see [llms.txt](https://docs.cubilock.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cubilock.com/profile-management/kiosk-settings/permitted-accessibility-services.md).

# Permitted Accessibility Services

In the **Kiosk Settings** tab of the **Edit Device Profile** screen in CubiLock, the **Permitted Accessibility Services** setting allows you to *specify which accessibility service apps are allowed to run on managed Android devices*. This controls the set of accessibility services that can operate under a device or work‑profile policy.<br>

### Navigation

Device Management → Device Profiles → Edit Profile → Kiosk Settings → Permitted Accessibility Services

#### **Overview**

Accessibility services are specialized Android services that can assist users with disabilities or provide alternate UI interaction capabilities (such as screen readers, switch access, voice‑linked navigation, or other assistive tools). All accessibility services require specific Android permissions and are closely controlled for security reasons.

In enterprise device management, uncontrolled accessibility services can be a security risk because they have broad access to UI content and input. To mitigate this, the **Permitted Accessibility Services** policy lets you *explicitly list which services are permitted*.

#### What This Setting Controls

| **Term**                    | **Meaning**                                                                                                                                                  |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Unspecified**             | No explicit list is defined. *All accessibility services supported by the system may be used* (including third‑party accessibility apps).                    |
| **Permitted Services List** | Only the listed accessibility services *and system built‑in accessibility services* are allowed to run. All other accessibility services are blocked.        |
| **Empty List**              | When set to an empty list, **only system built‑in accessibility services** (e.g., TalkBack) are permitted; no third‑party accessibility services can be used |
|                             |                                                                                                                                                              |

#### Examples of Use Cases

| **Scenario**                                                                     | **Recommended Setting**                                                                                            |
| -------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| Devices used by employees with special accessibility needs                       | List specific accessibility services (e.g., screen readers or switch access).                                      |
| Devices in kiosk/retail environments where accessibility features are not needed | Use an *empty list* so only built‑in services are allowed, preventing external accessibility tools from operating. |
| General corporate devices where accessibility support is optional                | Leave as *Unspecified* to allow all services when needed.                                                          |

#### **How to Configure**

1. Open **Device Profiles** and choose the profile to edit.
2. Go to **Kiosk Settings**.
3. Select **Permitted Accessibility Services**.
4. Use the toggles to *allow the packages* that represent the accessibility services you want permitted.
5. Save the profile.

When applied, only the selected accessibility services (plus built‑in Android services) will be permitted to function on enrolled devices.
