AgentComparison
Risk checklist ยท Documentation-led

AI agent privacy and approval checklist

An agent that can read your inbox, spend money or run code can also make a mistake in your name. Before you connect anything, you need answers to eight questions. This page gives the questions, explains why each matters, and shows what the vendors of 16 agents publish about them.

Checked 1 October 20265 of 17 records contain a vendor privacy statementVendor statements, not audits

The eight questions

  1. What can it do without asking me? Look for named modes such as draft-only, ask-first or independent. Several vendors recommend setting boundaries yourself rather than relying on defaults.
  2. Which actions are hard to undo? Sending email, paying, deleting files and pushing code are different from drafting. Check that the agent pauses before those. Instinct's terms warn that safeguards may not prevent unintended actions, and Meta warns of unexpected actions from Muse.
  3. Whose identity does it act under? Wajo says Fo emails from its own address, not yours. Other agents act in your connected accounts. Know which one you are getting before it writes to your contacts.
  4. How does it pay? Wajo describes single-use cards so the merchant never sees your real card. Most agents in our records state nothing on payments. Do not give an agent a card without a limit you control.
  5. What is kept after you disconnect? Instinct's privacy policy and OpenAI's dots FAQ each say disconnecting does not automatically delete indexed or retained data. Ask how to delete it.
  6. Is your content used to train models? Comma and Wajo say no for the data types they name. Instinct's terms permit model-improvement use with opt-out. Where a vendor is silent in our records, that is a gap, not a promise.
  7. Can you see and edit its memory? OpenAI says individual dot memories cannot currently be viewed or edited. Check this for every agent that remembers you.
  8. Who else can see your tasks? Wajo says a human team steps in when AI alone cannot finish a task. Ask what that human can see and when.

What the vendors say, agent by agent

Each row comes from the agent's record. "Not established" means we did not find a statement in the sources we read. It does not mean the vendor has no policy.

AgentApproval and permission statementsPrivacy and retention statements
ChatGPT workspace agentsEnd-user and shared authentication differ App instructions do not grant access Shared connections can act for their ownerNot established in our sources.
Claude CodeAnthropic says terminal Claude Code asks permission before changing files or running commands; configured modes and integrations still need review.Not established in our sources.
CommaVendor says computers stay read-only until more access is allowed Task decisions wait in Needs Review; ask for draft-only work if preferredComma says conversations, prompts and files are not used for training, personal data is not sold, and app access is scoped and revocable. These are vendor claims, not an audit.
DevinDocumentation shows IDE takeover and an interactive browserNot established in our sources.
FinEscalation and access controls need dedicated source verificationNot established in our sources.
Fo by WajoVendor says Fo sends email from its own address, never as you Single-use payment cards are described; final spending approvals need verification Human team may step in when AI alone cannot finish a taskWajo says real card details are not exposed to Fo or the merchant, email is sent from its own address, credentials stay private, and data is not used to train third-party models. Vendor statements, not an independent audit.
InstinctPublic terms describe connected-service access and actions, and warn safeguards may not prevent unintended actions. Check your actual approval and account settings.Public terms permit model-improvement/training use subject to opt-out, with safety-review exceptions; Vault materials are excluded from training under those terms. The privacy policy says disconnecting a service does not automatically delete indexed data; external-data deletion is available in Workspace. These are public policy statements, not our independent audit.
LangGraphDevelopers implement oversight and permission boundariesNot established in our sources.
LucasVendor says users approve connected accounts, external actions and data accessLucas publishes a policy covering messages, connected apps and memory, with access/correction/deletion request rights and stated legal/security retention exceptions. It is not an independent privacy audit.
ManusMinimum permission and approval controls not verifiedNot established in our sources.
Microsoft Copilot StudioTenant, connector and governance scope need separate documentationNot established in our sources.
MuseMeta recommends defining boundaries and reviewing actionsNot established in our sources.
OpenAI dotsPlugin access is managed in ChatGPT Custom Rules add boundaries but cannot override safety requirements Enterprise admin access is off by default; app authorization and device/cloud permissions are separate.OpenAI says content is encrypted in transit and at rest. Disconnecting plugins does not erase retained context. Individual dot memories are not currently editable. These are vendor statements, not an audit.
PokeConnect supported integrations explicitly. Detailed write approval and retention controls need further verification.Not established in our sources.
Replit AgentPlan mode permits review before code or data changesNot established in our sources.
Salesforce AgentforceData access, agent governance and configured actions need verificationNot established in our sources.
Cue by ManusManus says each agent has its own email, phone number, wallet and computer, and that you set direction and make the final call. Transaction limits were not detailed in the source we read.Not established in our sources.

How to use this

Start with the agent's record, then ask the vendor the questions where the table says "not established". Connect one low-risk account first, keep sensitive accounts and payment cards out until you have answers, and review what it did after the first week. We have not tested any agent. Statements here are the vendors' own and may have changed since 1 October 2026. See the methodology and report an error. For personal agents specifically, see the permissions guide.