Muse's Sentinel Permissions, Explained

Sentinel is the gatekeeper inside Muse: the agent proposes, Sentinel allows, denies, or asks. How the permission model works and how to set yours up safely.

Jolly holding a glowing shield with a lock symbol

An agent that can spend your money and send your email needs a permission system you can trust. Meta’s answer is Sentinel: a separate system that sits between Muse and the outside world and rules on every action. It is the least glamorous part of the product. Understanding it is the difference between using Muse confidently and using it nervously. For the everyday habits that go with it, see our beginner’s guide to AI agent privacy and safety.

The short version

  • Muse proposes actions. Sentinel, a separate system, is the sole authority that allows, denies, or asks.
  • Permissions split into read and write. Reading is easy to grant; writing and spending always involve you.
  • Approvals are specific: one action, one recipient, one amount. A yes in chat is not a permission.
  • Start with read-only access and expand deliberately. Review what you have granted.

The Core Idea: Propose vs Decide

Most assistants bundle thinking and doing into one system. Muse splits them. Muse figures out the plan; Sentinel checks each step against your policies before anything leaves the virtual machine. Sentinel is the sole permission authority for connector actions and network traffic. For every proposed action, Sentinel returns one of three answers: allowed, denied, or ask.

This split keeps the part of the system that reads untrusted web pages away from the decision about what leaves your machine. If a prompt injection tricks Muse into wanting something shady, Sentinel still has to approve it, and Sentinel does not read web pages. For why that boundary matters, see the Hunterbrook investigation into Muse compiling target lists of private individuals on request.

Read Is Easy. Write Is Gated.

Sentinel treats reading and writing as different universes. “Check my calendar for conflicts” is the kind of request that sails through. “Book the meeting,” “send the email,” and “buy the shoes” stop for a human. That asymmetry matches the stakes: reading informs you, writing commits you.

When Sentinel asks, the approval is a strict capability, not a suggestion: it is bound to a specific connector or destination, a specific action, and where money is involved, a specific amount. You can grant it once, for a session, for a task, for a time window, or permanently. A blanket “yes to everything” would defeat the design. When in doubt about a new connector, ask Muse what access it wants and why before granting anything. The answer tells you whether the request is reasonable, and it puts the agent’s reasoning on the record.

Your Credentials Stay Out of Reach

Muse never sees your real passwords or card numbers. Meta swaps credentials in at the network boundary, so the model itself only ever handles surrogate tokens. For purchases from merchants it does not know, it uses single-use virtual cards tied to one seller, one amount, and a short validity window. Even if someone talked the agent into revealing what it holds, there would be nothing useful to reveal.

Setting Up Permissions Safely

Think in tiers. Start with read-only connections: calendar, inbox, notes. Let Muse summarize and draft for a few days and check its work against reality. Add write access one tool at a time, and keep every write action on explicit approval until the pattern earns your trust. Spending comes last, with a ceiling you set yourself.

Review your grants the way you review app permissions on your phone: periodically, and with suspicion toward anything you do not remember enabling. Revoke generously. A connection you no longer use is pure risk with no upside, and reconnecting takes a minute. In late September, Muse’s Mac app synced a user’s private message history through a system-level permission the user said he never knowingly granted. Meta called Messages access opt-in. Whatever the truth of that dispute, the lesson survives it: check what your agent can touch.

What Sentinel Cannot Do for You

Sentinel gates the agent. It does not gate you. The most common failure mode is approval fatigue: after the twentieth correct approval card, you stop reading and start tapping. Attackers know this, which is why the approval card shows the specific action, recipient, and amount. Read it every time, especially the recipient. A second limit: Sentinel cannot tell whether you actually wanted the thing you approved. If you tell Muse to pay an invoice and the invoice is fraudulent, Sentinel will faithfully ask and you will faithfully approve. The permission system protects the boundary between you and the agent. What crosses that boundary on your instructions is your responsibility.

A final note: this is a young product and the details will evolve. Meta has published the architecture in unusual depth for a consumer product, but screens, defaults, and policies will change. Treat this article as the model and the permission prompts in front of you as the manual.

The safest Muse user knows exactly what they granted.

Keep reading