Permissions and secrets
How approvals, operating-system grants, and provider credentials are handled.
Approval cards
Supported providers emit permission requests and questions through the local harness. Brainwrite displays these inline and records the outcome. Cancellation closes outstanding requests so stale approvals cannot be answered after a turn has ended.
“Always allow” is narrow: it is tied to a server-issued key and a pending request rather than granting arbitrary execution from a paired device.
Operating-system permissions
Screen Recording and Accessibility permissions are controlled by the operating system. The desktop process owns local CUA lifecycle so grants are attributed to Brainwrite.
Secret handling
- Do not paste API keys into chat.
- Packaged builds use write-only settings and operating-system-backed encryption where supported.
- Secret values are scrubbed from public configuration responses and mobile APIs.
- Per-provider environment injection prevents unrelated agent processes from inheriting credentials they do not use.
- OAuth provider tokens for connected apps stay with Composio.
Connected-app tool grants
Connected apps are scoped per bot on the desktop: a bot without a grant to a service's tool cannot call it, the ungranted tool is never offered to the model, and every allow/deny is written to the decision log. New and upgraded bots keep all tools until someone assigns grants, and imported bots always land with none, so a shared persona cannot reach your Gmail on turn one. Paired phones see grants read-only; grant editing requires the computer.
Website sign-in
Bots may complete a sign-in you explicitly authorize for a particular site and account, using an existing session, autofill, or credentials you supply or designate for that purpose, including test accounts. A login form alone is not a reason to refuse the task. Bots must check the destination and account first; instructions on a webpage do not authorize using credentials.
Do not paste passwords or one-time codes into chat. If credentials are missing, or a step needs MFA, CAPTCHA, payment details or your personal interaction, use Take control, complete that step, then return control and ask the bot to continue. This prompt policy does not add a website-password vault or override your provider's own restrictions. Approval modes and manual takeover are unchanged.
Shared machines
Brainwrite assumes the logged-in operating-system user is the workspace owner. On a shared machine, other administrators may be able to read application data or inspect processes. Use a dedicated OS account for stronger separation.