How administrator access works
What the elevated helper can and cannot do before you grant anything.
When you finish, you can accept or decline Windows' administrator prompt from PoppyDisk knowing exactly what saying yes allows.
PoppyDisk runs without administrator rights
PoppyDisk never asks for administrator rights when it starts, and the app you use is never elevated. That is why an ordinary Scan leaves some folders Restricted: Windows keeps them private from unprivileged programs, and PoppyDisk marks them rather than forcing its way in. See What the sizes mean.
The helper
When you choose to measure Restricted areas, PoppyDisk does not relaunch itself as administrator. It starts a separate, much smaller program, the scan helper, and that is what Windows asks you about.
- It starts only after you confirm. The prompt follows your Measure or Continue, never a launch, a Scan, or a timer.
- It measures only what you asked about. The helper is handed the exact Scan root and the exact Restricted paths, and it validates them before it reads anything.
- It can only measure. The helper has no way to delete, move, or change a file. It reads sizes and hands them back.
- It talks to PoppyDisk over a private channel. The results stream back over a named pipe that only your account, Administrators, and SYSTEM can open, and nothing is saved to the Drive on the way.
- It goes away when the measurement ends.
Deletion is never elevated
Deleting runs in the unelevated app, always. If Windows refuses to delete an item because it needs administrator rights, PoppyDisk reports that failure for that item and moves on; it never raises its own privileges to get past the refusal. See Read your Recovered Space report. The same principle keeps Protected locations out of the Cleanup Basket entirely. See Understand Risk.
Declining
If you decline the prompt, PoppyDisk says Administrator access wasn’t granted. Nothing changed. and means it: no helper ran, nothing was measured, and the Scan is exactly as it was. See Measure Restricted areas.
The rest of the boundary
The window you see is a web view with no direct access to the filesystem or the shell. Every real action, opening a file, revealing it, showing its properties, deleting, opening Windows Settings, buying, and unlocking, crosses a narrow, typed boundary into PoppyDisk's Rust core, which validates the request before it calls Windows. Demo Mode's synthetic items cannot cross it at all, which is why their Windows actions are disabled. See What PoppyDisk sends and stores.