Meta Muse: permissions, approvals and data
Muse is Meta's personal agent, available in the US and Canada. Meta published a long technical post, How We Built Safety Into Muse (8 September 2026), describing how it limits what the agent can do and see. This guide summarises that post for people deciding whether to connect accounts. Everything below is Meta's description of its design. We have not tested Muse, and Meta itself says Muse can make mistakes and is not immune to attack.
The design in brief
- Your own cloud computer. Meta says each user gets a dedicated virtual machine where Muse runs and where data and credentials for connected services are stored.
- A separate permission authority. Meta says an agent called Sentinel, which Muse cannot override, is the only authority for connector actions and network egress. Muse proposes an action and only Sentinel can grant it.
- Credentials the model never sees. Meta says the agent only handles surrogate tokens and the real credential is inserted at the network boundary after an action is approved, so a manipulated agent cannot reveal it.
- Assume attack. Meta says the system is designed on the assumption that the agent may be attacked through content it reads, and uses layered defences: model training, labelling of untrusted input, classifiers, and approvals for actions that move data out of the VM.
Approvals
| Topic | What Meta says |
|---|---|
| When it asks | Sentinel can allow, deny or ask. Read-only, previously allowed or low-risk actions can proceed without interruption. Meta says the aim is friction where consent matters, not asking about everything, and that it expects to tune this over time. |
| Where you approve | A dialog in the Muse client, not in your chat with Muse, describing the exact action. |
| How long an approval lasts | Meta says approvals are strict capabilities tied to a connector, destination and use, and can be one-time, session, task, time-bounded or perpetual. Sentinel decides which options to offer. |
| Read versus write | Where the service supports it, Muse separates read and write access, and offers finer controls than the usual OAuth scopes. |
| Meta says the email connector filters out one-time codes, password-reset links and login magic links, so the agent cannot be used to take over other accounts. | |
| Purchases | Meta says every payment needs a human approval showing the exact details. It says Muse uses a wallet with Stripe Link at launch (Shop Pay "coming soon") that issues a single-use card tied to one merchant, one amount and a limited time. |
| Browser | Meta says you can watch and take over, the agent pauses while you do, passwords go straight to secure storage, and classifiers block or prompt for risky forms and suspected prompt injection. |
Data and training
- Meta says Muse does not share your conversations or VM data with Meta ad systems, but that your browsing by Muse appears as your activity, so a purchase or reservation can indirectly influence ads you see.
- Meta says conversations and tool-call trajectories are used to train new model versions after sanitising personal information, and that you can opt out in Muse settings.
- Meta says current operational policies restrict its staff's access to your VM but do not prevent access when necessary to support, secure or operate the service. It describes a "Muse Confidential VM", planned for later this year, intended to prevent Meta access, which is not available at the time of the post.
- Meta says you can inspect, edit and download your files, including Muse's memory about you.
Security programme
Meta says it opened its Muse bug bounty to the public, paying up to $300,000 for valid reports, including up to $130,000 for prompt injection that affects one user.
What this does not tell you
- It is a design description by the vendor, written at launch. Independent audits or test results were not part of the source.
- Meta says it will change the approval balance over time, so check the current settings.
- The September 29 Muse for Small Business announcement says nothing publishes, sends or spends without your approval, and lists new business connectors. Check the Muse app for current connector permissions.
Compare with other personal agents in our Instinct vs Muse vs OpenAI dots guide, use the approval checklist, and see the Muse record. Spot an error? Tell us.
Source: Meta AI Research, How We Built Safety Into Muse (8 September 2026).