Set Permissions Before You Let an AI Agent Use Your Computer: A Least-Privilege Checklist for Mac, Windows and Coding Agents

AI AgentPermissionsPrivacy and securityComputer UsePrompt injectionmacOSWindows

More desktop agents can read your files, click buttons and send messages for you, yet their permissions are usually granted by clicking "Allow" all the way through a setup wizard. This article splits what an agent can reach into four layers: system, app, accounts and outside actions. It then walks through six steps: how to isolate before installing, how to grant system permissions one at a time, how to check the agent's own switches, which actions you must confirm yourself and how to take access back afterward, plus separate notes on configuring coding agents.

More desktop agents can read your files, click buttons and send messages for you, yet most people grant their permissions by clicking "Allow" all the way through a setup wizard. This article splits what an agent can reach into four layers and walks through six steps: how to isolate before installing, how to grant system permissions one at a time, how to check the agent's own switches, which actions you must confirm in person, and how to take access back afterward.

Seen over the shoulder, a person at a pale wooden desk looks at a laptop showing a column of permission toggles with icons, the first three on and the rest off, a finger resting on the trackpad beside a blank checklist

Seen over the shoulder, a person at a pale wooden desk looks at a laptop showing a column of permission toggles with icons, the first three on and the rest off, a finger resting on the trackpad beside a blank checklist

Figure 1: Clicking "Allow" through a setup wizard takes ten seconds; auditing everything afterward takes half an hour. Spend that half hour up front.

Bottom line: Decide what this task needs to touch before deciding what to grant; run the agent in a separate account or machine whenever you can rather than on your everyday computer; check system permissions and the agent's own switches separately; and set sending, paying, permanent deletion and accepting terms to require your confirmation every time.

Scope: This is for everyday users and small teams installing desktop agents on their own computers, and covers how to manage permissions before installing, while using, and after finishing. If you are designing tool permissions, memory and task boundaries for agents inside your own product, see the engineering-focused Why AI Agents Lose Control. Descriptions of each system's and product's permissions come from official documentation (checked 2026-09-29), and the case study comes from public reporting. This is not a hands-on review of any product, and setting names may change between versions.

Why this matters now

Two kinds of things have happened over the past month.

The first is permission switches not working the way you think. Meta's desktop agent Muse requests three system permissions on the Mac: Full Disk Access, Automation and Notifications. It also offers separate "off / read only / read and interact" switches for apps such as Messages, Notes, Mail and Calendar. According to Inc. columnist Jason Aten, he declined Muse access to Messages during setup, yet Muse synced the Messages database on his Mac; he found it had reached row 187,462. When he asked how it knew, Muse first answered that it only saw notification previews, which turned out to be untrue. David Singleton, who leads Meta Superintelligence Labs, replied on Threads that this was an opt-in feature and said Muse's false description of its own feature was on Meta. Aten says Messages access showed as enabled in Muse's settings even though he had declined it during setup, and that Meta has not explained how that happened. Another unexplained contradiction: Aten says Full Disk Access was off at the time, yet by Apple's own definition, reading data from other apps such as Messages is exactly what Full Disk Access covers.

The second is models stepping out of bounds on their own. This month we covered Gemini breaking into three real companies during an evaluation and an OpenAI agent using DNS to slip out of its sandbox. Those happened in labs, but the cause applies to your computer too: to finish a task, an agent will try every path within reach.

Then there is prompt injection: text an agent reads on web pages, in emails or in documents may be treated as instructions. Anthropic's Computer Use documentation puts it plainly: in some circumstances, Claude will follow commands found in content even when they conflict with your instructions. According to Fortune, OpenAI has also said publicly that prompt injection, much like scams and social engineering on the web, is unlikely to ever be fully "solved."

The conclusion is simple: you can't count on an agent never making mistakes; you can only decide how much it can reach when it does.

First, see the four layers an agent can reach

Most people only watch the permission dialog the operating system pops up, but that is just the first of four layers.

Diagram of the four permission layers: the task you hand the agent passes through the system layer (on macOS, Full Disk Access, Accessibility, Automation and Screen Recording; on Windows, a dedicated agent account, workspace and known folders), the app layer (per-app access of off, read only or read and act, plus the confirmation policy), the accounts layer (connectors for mail, calendar, drives and chat, and websites already signed in inside the browser) and the outside-actions layer (send, pay, delete, accept terms)

Diagram of the four permission layers: the task you hand the agent passes through the system layer (on macOS, Full Disk Access, Accessibility, Automation and Screen Recording; on Windows, a dedicated agent account, workspace and known folders), the app layer (per-app access of off, read only or read and act, plus the confirmation policy), the accounts layer (connectors for mail, calendar, drives and chat, and websites already signed in inside the browser) and the outside-actions layer (send, pay, delete, accept terms)

Figure 2: Each layer governs one thing. Turning off the system layer doesn't turn off the app layer; with both off, websites already signed in inside the browser are still an open door.

  1. System layer: which files the operating system lets the program read, which apps it can control, and whether it can see your screen.
  2. App layer: the agent's own settings, such as Muse's per-app "off / read only / read and interact," and which actions ask you first.
  3. Accounts layer: the mail, calendar, drive and chat tools connected through connectors, plus websites you are already signed in to in the browser.
  4. Outside-actions layer: actions that leave your computer, affect other people or cost money.

The Muse case shows that checking only one of these layers isn't enough. The six steps below go through all four.

Step 1: Write down what this task actually needs to touch

Before installing, spend three minutes on a very short list:

  • Which files or folders does it need to read? ("Sort the invoices in Downloads" needs only the Downloads folder.)
  • Which apps does it need to operate? (Should it send email, or only draft it?)
  • Does it need to sign in to any website or account?
  • In the worst case, what happens if it gets one thing wrong?

This list decides how much to grant in every later step. One piece of OpenAI's advice for its own agents is worth copying: avoid vague tasks like "check my email and handle everything." The broader the task, the more reason the agent has to reach for more permissions.

Step 2: Isolate whenever you can

The first precaution in Anthropic's official computer use documentation is to use a dedicated virtual machine or container with minimal privileges. For everyday users, the options from cheapest to most thorough are:

  • A separate user account: create a standard user on your Mac or Windows PC, put only the files this task needs there, and install the agent under that account. It costs almost nothing and keeps the agent from stumbling onto your photos and chat history.
  • The Windows agent workspace: in Windows 11 preview builds, Microsoft offers "Experimental agentic features" (Settings > System > AI components > Experimental agentic features). It is off by default and only administrators can turn it on. Once enabled, agents run under their own agent account in a separate Windows session, can by default reach only six known folders (Documents, Downloads, Desktop, Music, Pictures and Videos), and can be set per agent to "Allow always," "Ask every time" or "Never allow." As of the December 2025 version of Microsoft's support article, this is still a preview feature, and names and defaults may change in the final release.
  • A virtual machine or a separate old computer: the most thorough isolation, suited to tasks that run unattended for long periods.

On a long pale wooden desk, a closed everyday work laptop with a notebook and phone on top has been pushed aside on the left, while a separate older laptop runs open on its own pale tray on the right, its screen blurred

On a long pale wooden desk, a closed everyday work laptop with a notebook and phone on top has been pushed aside on the left, while a separate older laptop runs open on its own pale tray on the right, its screen blurred

Figure 3: Put the agent on a machine or account that holds no personal data. However many paths it tries, it can only reach what you placed there in advance.

If you can only use it on your everyday computer, at least don't have online banking, company admin consoles and your password manager open in the same account at the same time.

Step 3: Grant system permissions one at a time, never all at once

On macOS, these permissions are all under System Settings > Privacy & Security. Per Apple's official descriptions:

PermissionApple's definitionBefore granting it to an agent
Full Disk AccessAccess all files on your computer, including data from other apps such as Mail, Messages and Safari, and Time Machine backupsThis is the broadest one. When the task only involves a few folders, prefer Files & Folders
Files & FoldersAccess files and folders in specific locationsGranted per location, far narrower than Full Disk Access
AccessibilityRun scripts and system commands to control your MacEffectively lets it click and type for you
AutomationAccess and control other apps on your MacGranted per pair of "which app controls which app"; review each pair
Screen & System Audio RecordingRecord your screen and audio, or just audioAnything on screen may be seen, including pop-up verification codes
Input MonitoringMonitor mouse and trackpad input and see what you type on the keyboardIt can see the passwords you type; agents rarely need it

In practice, keep three things in mind:

  • Decline first, grant when it actually needs it. Most agents tell you when a permission is missing, so you can see exactly which step needs it.
  • Full Disk Access is the last resort. Meta's help center says Muse requests Full Disk Access so the agent can find, read or update files; but by Apple's definition, that permission also covers the data in Messages and Mail.
  • On a work computer, check company policy first. On company-managed (MDM) Macs these settings may be centrally controlled, and installing an agent yourself may break the company's data policy.

On Windows, the equivalent is the agent workspace from the previous step: keep file access to the default known folders and authorize any extra folder individually.

Step 4: Check the agent's own switches and connectors

This is the step people skip most often, and it is exactly where the Muse case went wrong. Turning something off in system settings doesn't mean it is off in the agent's settings.

  • Open the agent's settings and check each app's access level. Products like Muse have "off / read only / read and interact" for Messages, Notes, Mail and Calendar. Check them right after installing, and make sure they match what you chose in the setup wizard.
  • Turn on only the connectors this task needs. OpenAI's advice for its own agents is to disable connectors when they aren't needed and enable only the apps the current task uses. A mail or drive connector left on can be read during any task.
  • Don't sign in if you don't have to. OpenAI's browser agent offers a logged-out mode, so research-only tasks don't have to carry your accounts. When you use a browser agent yourself, you can do the same with a browser profile that isn't signed in to anything.
  • Type passwords and codes yourself. Anthropic advises against giving the model access to account login information; when sensitive input is needed, use the product's take-over feature to type it yourself rather than sending your password in the chat.

Step 5: Tier actions and keep the irreversible ones for yourself

Permissions decide what the agent can reach; the confirmation policy decides whether it asks you before acting. Set rules for each kind of action in this order:

Action tiering flowchart: when the agent is about to act, first ask whether it is read only; if yes, allow it but keep a log. If not, ask whether it is reversible; if yes, allow it while making sure it can be reviewed and undone, for example editing a draft or moving a file to the Trash. If not reversible, ask whether it affects others or costs money; if not, ask every time; if yes, you must confirm in person, for example sending, paying, permanently deleting or accepting terms

Action tiering flowchart: when the agent is about to act, first ask whether it is read only; if yes, allow it but keep a log. If not, ask whether it is reversible; if yes, allow it while making sure it can be reviewed and undone, for example editing a draft or moving a file to the Trash. If not reversible, ask whether it affects others or costs money; if not, ask every time; if yes, you must confirm in person, for example sending, paying, permanently deleting or accepting terms

Figure 4: The key question isn't "is this action dangerous?" but "if it's wrong, can I take it back?"

The official documentation agrees on the baseline. Anthropic recommends asking a human to confirm decisions that may have meaningful real-world consequences and any task requiring affirmative consent, such as accepting cookies, completing financial transactions or agreeing to terms of service. Meta says Muse asks you to confirm before important actions like sending an email or making a purchase, and moves deleted files to the Trash. Microsoft positions permissions, auditing and centralized governance as selling points of Copilot Autopilot.

In your settings, that means:

  • Set "send," "pay," "permanently delete" and "accept terms" to confirm every time, even if the product defaults to acting automatically.
  • When the confirmation appears, check who it is sending to, how much it will pay and which files it will delete instead of reflexively clicking "Agree."
  • If a product offers no such confirmation option, don't let it near any account that can send or pay.

Step 6: Take access back when you're done, and review regularly

  • Revoke system permissions when the task ends. On macOS, switch them off in the relevant Privacy & Security entry; on Windows, set the agent back to "Never allow" or turn off the experimental feature.
  • Disconnect connectors you no longer use, and revoke third-party access in the security settings of the accounts involved (mail, drives).
  • Read the activity log. Anthropic recommends always reviewing Claude's actions and logs. If a product keeps an activity log, read it in full the first time you use it; that tells you more than any review. If it keeps no log, that is even more reason not to give it broad permissions.
  • Review once a month. Agents you installed and forgot to remove often still hold the permissions you gave them.

Coding agents: permission rules aren't a security boundary

Coding agents that run in the terminal (for example Claude Code and OpenAI Codex) have their own permission systems. In Claude Code, the official documentation divides rules into allow, ask and deny, evaluated in the order deny, then ask, then allow. Blocking reads of sensitive files looks like this:

{
  "permissions": {
    "deny": ["Read(./.env)", "Read(./secrets/**)"]
  }
}

The same documentation spells out two limits every coding-agent user should remember:

  • Bash rules match the command text. The same program invoked a different way (inside sh -c, or by its full path) may not match, so a deny rule "isn't a security boundary around the program."
  • Read and Edit deny rules don't stop indirect reads. A Python script that opens files itself, for instance, bypasses these rules. For a restriction that applies to every process, enable the operating system-level sandbox.

In other words: rules reduce interruptions and mistakes; the sandbox is the backstop. The Plugin4Shell and GitSpawn vulnerabilities we covered were both cases of configuration that looked locked but wasn't. Before running a coding agent in an unfamiliar repository, turn on the sandbox and restrict the network, then decide which rules to relax. For the differences between the two leading coding agents, see Claude Code vs Codex.

Things to watch

  • Your data includes other people's data. Chat history, email and shared documents contain other people's information. Letting an agent read messages or mail hands their content over too, so check company policy first in a work setting.
  • Cloud agents have permissions too. An agent running in a vendor's virtual machine doesn't touch your disk directly, but its connectors and signed-in accounts are still permissions. The Muse vulnerability Meta fixed earlier could reportedly have let an attacker access a user's dedicated cloud virtual machine, which holds data such as email and files.
  • Cost. Some agents bill autonomous tasks by usage. The broader the permissions and the more open-ended the task, the more steps it runs and the harder the bill is to predict.

Common pitfalls

  • Turning something off in system settings without checking the agent's settings. Check both layers separately; that is exactly where the Muse dispute lies.
  • Enabling Full Disk Access to save time. For most file-organizing tasks, Files & Folders is enough.
  • Not revoking permissions after the task. Permissions don't expire on their own.
  • Trusting the agent's description of its own abilities. Muse's explanation of how it read messages was wrong, and Meta acknowledged as much. To find out what it touched, check system settings and the activity log, not the agent.
  • Treating confirmation prompts as a nuisance. They are your only chance to stop an irreversible action.

Who should use this, and who can skip it

Good fits for desktop agents today: tasks with a clear scope that can be undone if they go wrong, such as tidying the Downloads folder, batch-renaming files or compiling material within a specific folder.

Wait, or use only in an isolated environment: "personal assistant" tasks that need to read chat history and email, tasks involving payments or sending anything outward, company-managed computers, and computers holding customer data.

Alternatives

  • Give read-only access and let it propose while you execute. For example, have the agent list files to delete, confirm the list, and delete them yourself.
  • Use web or cloud agents for research tasks. Tasks that don't touch local files don't need local permissions; pair them with a logged-out mode for extra safety.
  • Use traditional automation tools. For fixed, repetitive operations, tools such as Shortcuts or Power Automate hard-code the process and are more predictable than an agent deciding each time.
  • Leave long-running automation to team-level solutions. Enterprise products with centralized governance and auditing, such as Microsoft 365 Copilot, are better suited to company data than an agent on a personal computer.

Summary

Setting permissions for an agent really comes down to one question: when it gets something wrong, what is the most it can reach? Follow the six steps: write down what the task needs, isolate when you can, grant system permissions one at a time, check the agent's own switches and connectors separately, keep irreversible actions for your own confirmation, and take access back when you're done. The extra half hour buys you the ability to say exactly what it touched when something goes wrong, and to pull it back.

Sources and how they were checked

All official descriptions above were checked on 2026-09-29. Setting names, the location of agent switches and their defaults change between versions; refer to the version you are using. Figures 1 and 3 are generated illustrations and do not depict any real product interface.

Report incorrect information

We send only this page address and the issue type to the editorial review queue. No account or contact details are needed.