Perplexity Computer Adds Automations: An Email or a Slack Message Can Wake the Agent, and Each Run Picks Up Where the Last One Left Off

On September 29 Perplexity added Automations to Perplexity Computer, its agent product, for standing tasks that need to run repeatedly. A task can run at a fixed time or be triggered by events in Slack, Gmail, Outlook, Linear and GitHub, with conditional filters, for example starting only when a particular sender emails asking for a decision. Each Automation combines instructions, a trigger, connected resources and its run history, and each run reads earlier results to continue from where it left off instead of starting over; it can also watch for missed deadlines and overdue replies and flag them. Credits are spent only on actual runs, not while waiting for a trigger; according to the help center, 100 credits equal $1, a run is skipped if credits run out, and the task is paused after repeated skips. Automations replace the old Scheduled Tasks panel, and existing scheduled tasks can be migrated when opened.

From "run on a schedule" to "run when something happens"

Scheduled tasks could only fire on the clock: check the inbox every hour, and run and spend credits even when nothing new has arrived. Event triggers reverse the order: the agent wakes only when an email arrives, a ticket changes status or a PR is merged. For things that genuinely need handling only a few times a week, that removes most of the empty runs.

"Continue from last time" is the other practical change. The vendor's example is a weekly project update: the agent carries forward last week's unresolved blockers instead of rebuilding the picture every Monday, and a pricing monitor compares this week's data with earlier results without re-establishing a baseline each time.

Letting outside email wake an agent brings the risk in too

Event triggers also mean that an email from outside, with untrusted content, can directly start an agent that can act on your accounts. Instructions hidden in the email body are a classic prompt injection entry point. When a publication found the feature being tested in Perplexity's client code, it raised the same concern.

Until the vendor publishes more detailed permission guidance, the safer approach is to keep trigger conditions narrow, limited to specific senders or labels, and have Automations produce drafts and reminders while keeping human confirmation for actions like sending, merging or paying.

Similar products are heading the same way

The same day, OpenAI announced dots, its always-on agents, at its developer conference, and Meta was expanding Muse's connectors. "Working in the background and waking on events" is becoming standard for agent products; the differences will be which apps the triggers cover, how fine-grained the permissions are, and whether you can trace which run did what when something goes wrong.

Scope note: features and billing rules come from Perplexity's official announcement and help center; the vendor has not published protections specific to prompt injection in Automations.

via: Perplexity official X post, Perplexity Academy: How to use Automations, Perplexity Help Center: Scheduled Tasks in Computer, RuntimeWire report