Skip to content
Agentic Workflowdocs
v0.8.2Install free

use the app / chat and agents

Browser control & safety

How agents use the browser in their own tab group, and the rules, locked actions, takeover and injection guard that keep you in control

With the Browser control skill, an agent can open pages, read them, click, type, choose options and scroll — using the logins you already have in this browser. These safeguards are enforced in code, around every action, so a page or a prompt can’t talk an agent out of them.

An agent works in its own tab, grouped and named after the agent (or after the team, when a team shares one tab group). It never uses the tabs you opened yourself unless its rules allow it.

While it works, a banner on the page shows what it is doing, with:

  • Pause / Resume — hold the next action.
  • Take over — pause and bring the tab to the front so you can do a step yourself.
  • Stop — end the agent’s turn.

Elements the agent acts on are highlighted, and each action is listed under the reply (“Clicked “Reserve””).

Each agent has rules — in the builder’s Rules tab — that decide whether an action is allowed, asks first or is blocked:

Preset What it means
Cautious Asks before anything that changes a page.
Balanced (default) Browses alone, asks before submitting forms.
Autonomous Acts alone within the locked rules.

Then fine-tune per action: reading pages, navigating and clicking, typing into forms, submitting forms, using your own tabs, each workflow, web search, handing work to teammates and each MCP server. Add sites it may only use, or must never use (patterns like *.bank.* work).

Clicks that commit something — Reserve, Book, Confirm, Send, Buy — count as submitting.

When an agent asks, a card shows what it wants to do, exactly what will be sent — the values as the tool will use them, such as the recipient and subject of an email or the inputs a workflow gets, with secrets masked — and which rule asked: Allow once, Always on this site (or Always allow), or Deny. A denied action is skipped and the agent continues without it.

Once you answer, the card leaves a receipt under the reply — Allowed once by you, Always on this site, Denied or You took over — with the time, so you can see later what you approved.

Some actions always need you, whatever the rules say:

  • Payments — the agent hands the step over: it stops before payment, and you finish it yourself.
  • Passwords and sign-in, sending messages or posts as you, and deleting data — always ask.

This also applies to the agent’s other skills, based on what a tool really does rather than its name:

  • Workflows — a workflow whose steps send something (for example a Gmail or Slack step set to Send), delete something (a Delete step, or an HTTP request using DELETE) or take a payment always asks, even if it is called “Daily digest”. Workflows it calls are checked too.
  • MCP tools — a tool the server marks as destructive always asks, and so does one whose name or description starts with sending, deleting or paying (send_email, “Removes stale rows”). A tool the server marks as read-only isn’t locked.

Web pages sometimes contain text written to manipulate AI agents (“ignore your instructions and…”). Page text is always treated as content, never as instructions — and so is everything else an agent gets from outside: web search results, MCP tools, workflows and teammates’ answers. The step list marks these results Page text treated as data. When a page looks like it is trying to instruct the agent, the step list shows Instructions in the page were ignored, and the rules still apply to everything the agent does next.

  • Browser control works best with a large cloud model; small on-device models may get stuck on multi-step pages.
  • Start agents on Cautious or Balanced, and use Test a rule in the Rules tab to check what would happen.
  • In teams, team rules can make every member stricter at once.
  • Agents only work while your browser is open.
Ask Aria