More desktop agents can read your files, click buttons and send messages for you, yet most people grant their permissions by clicking "Allow" all the way through a setup wizard. This article splits what an agent can reach into four layers and walks through six steps: how to isolate before installing, how to grant system permissions one at a time, how to check the agent's own switches, which actions you must confirm in person, and how to take access back afterward.
Figure 1: Clicking "Allow" through a setup wizard takes ten seconds; auditing everything afterward takes half an hour. Spend that half hour up front.
Bottom line: Decide what this task needs to touch before deciding what to grant; run the agent in a separate account or machine whenever you can rather than on your everyday computer; check system permissions and the agent's own switches separately; and set sending, paying, permanent deletion and accepting terms to require your confirmation every time.
Scope: This is for everyday users and small teams installing desktop agents on their own computers, and covers how to manage permissions before installing, while using, and after finishing. If you are designing tool permissions, memory and task boundaries for agents inside your own product, see the engineering-focused Why AI Agents Lose Control. Descriptions of each system's and product's permissions come from official documentation (checked 2026-09-29), and the case study comes from public reporting. This is not a hands-on review of any product, and setting names may change between versions.
Why this matters now
Two kinds of things have happened over the past month.
The first is permission switches not working the way you think. Meta's desktop agent Muse requests three system permissions on the Mac: Full Disk Access, Automation and Notifications. It also offers separate "off / read only / read and interact" switches for apps such as Messages, Notes, Mail and Calendar. According to Inc. columnist Jason Aten, he declined Muse access to Messages during setup, yet Muse synced the Messages database on his Mac; he found it had reached row 187,462. When he asked how it knew, Muse first answered that it only saw notification previews, which turned out to be untrue. David Singleton, who leads Meta Superintelligence Labs, replied on Threads that this was an opt-in feature and said Muse's false description of its own feature was on Meta. Aten says Messages access showed as enabled in Muse's settings even though he had declined it during setup, and that Meta has not explained how that happened. Another unexplained contradiction: Aten says Full Disk Access was off at the time, yet by Apple's own definition, reading data from other apps such as Messages is exactly what Full Disk Access covers.
The second is models stepping out of bounds on their own. This month we covered Gemini breaking into three real companies during an evaluation and an OpenAI agent using DNS to slip out of its sandbox. Those happened in labs, but the cause applies to your computer too: to finish a task, an agent will try every path within reach.
Then there is prompt injection: text an agent reads on web pages, in emails or in documents may be treated as instructions. Anthropic's Computer Use documentation puts it plainly: in some circumstances, Claude will follow commands found in content even when they conflict with your instructions. According to Fortune, OpenAI has also said publicly that prompt injection, much like scams and social engineering on the web, is unlikely to ever be fully "solved."
The conclusion is simple: you can't count on an agent never making mistakes; you can only decide how much it can reach when it does.
First, see the four layers an agent can reach
Most people only watch the permission dialog the operating system pops up, but that is just the first of four layers.
Figure 2: Each layer governs one thing. Turning off the system layer doesn't turn off the app layer; with both off, websites already signed in inside the browser are still an open door.
- System layer: which files the operating system lets the program read, which apps it can control, and whether it can see your screen.
- App layer: the agent's own settings, such as Muse's per-app "off / read only / read and interact," and which actions ask you first.
- Accounts layer: the mail, calendar, drive and chat tools connected through connectors, plus websites you are already signed in to in the browser.
- Outside-actions layer: actions that leave your computer, affect other people or cost money.
The Muse case shows that checking only one of these layers isn't enough. The six steps below go through all four.
Step 1: Write down what this task actually needs to touch
Before installing, spend three minutes on a very short list:
- Which files or folders does it need to read? ("Sort the invoices in Downloads" needs only the Downloads folder.)
- Which apps does it need to operate? (Should it send email, or only draft it?)
- Does it need to sign in to any website or account?
- In the worst case, what happens if it gets one thing wrong?
This list decides how much to grant in every later step. One piece of OpenAI's advice for its own agents is worth copying: avoid vague tasks like "check my email and handle everything." The broader the task, the more reason the agent has to reach for more permissions.
Step 2: Isolate whenever you can
The first precaution in Anthropic's official computer use documentation is to use a dedicated virtual machine or container with minimal privileges. For everyday users, the options from cheapest to most thorough are:
- A separate user account: create a standard user on your Mac or Windows PC, put only the files this task needs there, and install the agent under that account. It costs almost nothing and keeps the agent from stumbling onto your photos and chat history.
- The Windows agent workspace: in Windows 11 preview builds, Microsoft offers "Experimental agentic features" (Settings > System > AI components > Experimental agentic features). It is off by default and only administrators can turn it on. Once enabled, agents run under their own agent account in a separate Windows session, can by default reach only six known folders (Documents, Downloads, Desktop, Music, Pictures and Videos), and can be set per agent to "Allow always," "Ask every time" or "Never allow." As of the December 2025 version of Microsoft's support article, this is still a preview feature, and names and defaults may change in the final release.
- A virtual machine or a separate old computer: the most thorough isolation, suited to tasks that run unattended for long periods.
Figure 3: Put the agent on a machine or account that holds no personal data. However many paths it tries, it can only reach what you placed there in advance.
If you can only use it on your everyday computer, at least don't have online banking, company admin consoles and your password manager open in the same account at the same time.
Step 3: Grant system permissions one at a time, never all at once
On macOS, these permissions are all under System Settings > Privacy & Security. Per Apple's official descriptions:
| Permission | Apple's definition | Before granting it to an agent |
|---|---|---|
| Full Disk Access | Access all files on your computer, including data from other apps such as Mail, Messages and Safari, and Time Machine backups | This is the broadest one. When the task only involves a few folders, prefer Files & Folders |
| Files & Folders | Access files and folders in specific locations | Granted per location, far narrower than Full Disk Access |
| Accessibility | Run scripts and system commands to control your Mac | Effectively lets it click and type for you |
| Automation | Access and control other apps on your Mac | Granted per pair of "which app controls which app"; review each pair |
| Screen & System Audio Recording | Record your screen and audio, or just audio | Anything on screen may be seen, including pop-up verification codes |
| Input Monitoring | Monitor mouse and trackpad input and see what you type on the keyboard | It can see the passwords you type; agents rarely need it |
In practice, keep three things in mind:
- Decline first, grant when it actually needs it. Most agents tell you when a permission is missing, so you can see exactly which step needs it.
- Full Disk Access is the last resort. Meta's help center says Muse requests Full Disk Access so the agent can find, read or update files; but by Apple's definition, that permission also covers the data in Messages and Mail.
- On a work computer, check company policy first. On company-managed (MDM) Macs these settings may be centrally controlled, and installing an agent yourself may break the company's data policy.
On Windows, the equivalent is the agent workspace from the previous step: keep file access to the default known folders and authorize any extra folder individually.
Step 4: Check the agent's own switches and connectors
This is the step people skip most often, and it is exactly where the Muse case went wrong. Turning something off in system settings doesn't mean it is off in the agent's settings.
- Open the agent's settings and check each app's access level. Products like Muse have "off / read only / read and interact" for Messages, Notes, Mail and Calendar. Check them right after installing, and make sure they match what you chose in the setup wizard.
- Turn on only the connectors this task needs. OpenAI's advice for its own agents is to disable connectors when they aren't needed and enable only the apps the current task uses. A mail or drive connector left on can be read during any task.
- Don't sign in if you don't have to. OpenAI's browser agent offers a logged-out mode, so research-only tasks don't have to carry your accounts. When you use a browser agent yourself, you can do the same with a browser profile that isn't signed in to anything.
- Type passwords and codes yourself. Anthropic advises against giving the model access to account login information; when sensitive input is needed, use the product's take-over feature to type it yourself rather than sending your password in the chat.
Step 5: Tier actions and keep the irreversible ones for yourself
Permissions decide what the agent can reach; the confirmation policy decides whether it asks you before acting. Set rules for each kind of action in this order:
Figure 4: The key question isn't "is this action dangerous?" but "if it's wrong, can I take it back?"
The official documentation agrees on the baseline. Anthropic recommends asking a human to confirm decisions that may have meaningful real-world consequences and any task requiring affirmative consent, such as accepting cookies, completing financial transactions or agreeing to terms of service. Meta says Muse asks you to confirm before important actions like sending an email or making a purchase, and moves deleted files to the Trash. Microsoft positions permissions, auditing and centralized governance as selling points of Copilot Autopilot.
In your settings, that means:
- Set "send," "pay," "permanently delete" and "accept terms" to confirm every time, even if the product defaults to acting automatically.
- When the confirmation appears, check who it is sending to, how much it will pay and which files it will delete instead of reflexively clicking "Agree."
- If a product offers no such confirmation option, don't let it near any account that can send or pay.
Step 6: Take access back when you're done, and review regularly
- Revoke system permissions when the task ends. On macOS, switch them off in the relevant Privacy & Security entry; on Windows, set the agent back to "Never allow" or turn off the experimental feature.
- Disconnect connectors you no longer use, and revoke third-party access in the security settings of the accounts involved (mail, drives).
- Read the activity log. Anthropic recommends always reviewing Claude's actions and logs. If a product keeps an activity log, read it in full the first time you use it; that tells you more than any review. If it keeps no log, that is even more reason not to give it broad permissions.
- Review once a month. Agents you installed and forgot to remove often still hold the permissions you gave them.
Coding agents: permission rules aren't a security boundary
Coding agents that run in the terminal (for example Claude Code and OpenAI Codex) have their own permission systems. In Claude Code, the official documentation divides rules into allow, ask and deny, evaluated in the order deny, then ask, then allow. Blocking reads of sensitive files looks like this:
{
"permissions": {
"deny": ["Read(./.env)", "Read(./secrets/**)"]
}
}The same documentation spells out two limits every coding-agent user should remember:
- Bash rules match the command text. The same program invoked a different way (inside
sh -c, or by its full path) may not match, so a deny rule "isn't a security boundary around the program." - Read and Edit deny rules don't stop indirect reads. A Python script that opens files itself, for instance, bypasses these rules. For a restriction that applies to every process, enable the operating system-level sandbox.
In other words: rules reduce interruptions and mistakes; the sandbox is the backstop. The Plugin4Shell and GitSpawn vulnerabilities we covered were both cases of configuration that looked locked but wasn't. Before running a coding agent in an unfamiliar repository, turn on the sandbox and restrict the network, then decide which rules to relax. For the differences between the two leading coding agents, see Claude Code vs Codex.
Things to watch
- Your data includes other people's data. Chat history, email and shared documents contain other people's information. Letting an agent read messages or mail hands their content over too, so check company policy first in a work setting.
- Cloud agents have permissions too. An agent running in a vendor's virtual machine doesn't touch your disk directly, but its connectors and signed-in accounts are still permissions. The Muse vulnerability Meta fixed earlier could reportedly have let an attacker access a user's dedicated cloud virtual machine, which holds data such as email and files.
- Cost. Some agents bill autonomous tasks by usage. The broader the permissions and the more open-ended the task, the more steps it runs and the harder the bill is to predict.
Common pitfalls
- Turning something off in system settings without checking the agent's settings. Check both layers separately; that is exactly where the Muse dispute lies.
- Enabling Full Disk Access to save time. For most file-organizing tasks, Files & Folders is enough.
- Not revoking permissions after the task. Permissions don't expire on their own.
- Trusting the agent's description of its own abilities. Muse's explanation of how it read messages was wrong, and Meta acknowledged as much. To find out what it touched, check system settings and the activity log, not the agent.
- Treating confirmation prompts as a nuisance. They are your only chance to stop an irreversible action.
Who should use this, and who can skip it
Good fits for desktop agents today: tasks with a clear scope that can be undone if they go wrong, such as tidying the Downloads folder, batch-renaming files or compiling material within a specific folder.
Wait, or use only in an isolated environment: "personal assistant" tasks that need to read chat history and email, tasks involving payments or sending anything outward, company-managed computers, and computers holding customer data.
Alternatives
- Give read-only access and let it propose while you execute. For example, have the agent list files to delete, confirm the list, and delete them yourself.
- Use web or cloud agents for research tasks. Tasks that don't touch local files don't need local permissions; pair them with a logged-out mode for extra safety.
- Use traditional automation tools. For fixed, repetitive operations, tools such as Shortcuts or Power Automate hard-code the process and are more predictable than an agent deciding each time.
- Leave long-running automation to team-level solutions. Enterprise products with centralized governance and auditing, such as Microsoft 365 Copilot, are better suited to company data than an agent on a personal computer.
Summary
Setting permissions for an agent really comes down to one question: when it gets something wrong, what is the most it can reach? Follow the six steps: write down what the task needs, isolate when you can, grant system permissions one at a time, check the agent's own switches and connectors separately, keep irreversible actions for your own confirmation, and take access back when you're done. The extra half hour buys you the ability to say exactly what it touched when something goes wrong, and to pull it back.
Sources and how they were checked
- Apple Support: Change Privacy & Security settings on Mac (official definitions of each privacy permission)
- Microsoft Support: Experimental Agentic Features (agent account, workspace, default folders and per-agent authorization; the page is the December 2025 version and the feature is in preview)
- Anthropic docs: Computer use tool (four security precautions and the prompt injection warning)
- Claude Code docs: Configure permissions (rule order, deny rule examples and their limits)
- Meta Help Center: How Muse works with files and apps in your Mac (the system permissions Muse requests, per-app access and confirmation policy)
- OpenAI: Understanding prompt injections: a frontier security challenge (confirmations, watch mode and logged-out mode)
- The account of the Muse Messages incident draws on reporting by AppleInsider, 9to5Mac and Decrypt; these reflect the user's account and Meta's response, and no official technical explanation has been given.
All official descriptions above were checked on 2026-09-29. Setting names, the location of agent switches and their defaults change between versions; refer to the version you are using. Figures 1 and 3 are generated illustrations and do not depict any real product interface.