AgentComparison
Safety guide ยท Meta documentation, attributed

Meta Muse: permissions, approvals and data

Muse is Meta's personal agent, available in the US and Canada. Meta published a long technical post, How We Built Safety Into Muse (8 September 2026), describing how it limits what the agent can do and see. This guide summarises that post for people deciding whether to connect accounts. Everything below is Meta's description of its design. We have not tested Muse, and Meta itself says Muse can make mistakes and is not immune to attack.

Checked 1 October 2026Source: Meta AI ResearchNo hands-on test

The design in brief

Approvals

TopicWhat Meta says
When it asksSentinel can allow, deny or ask. Read-only, previously allowed or low-risk actions can proceed without interruption. Meta says the aim is friction where consent matters, not asking about everything, and that it expects to tune this over time.
Where you approveA dialog in the Muse client, not in your chat with Muse, describing the exact action.
How long an approval lastsMeta says approvals are strict capabilities tied to a connector, destination and use, and can be one-time, session, task, time-bounded or perpetual. Sentinel decides which options to offer.
Read versus writeWhere the service supports it, Muse separates read and write access, and offers finer controls than the usual OAuth scopes.
EmailMeta says the email connector filters out one-time codes, password-reset links and login magic links, so the agent cannot be used to take over other accounts.
PurchasesMeta says every payment needs a human approval showing the exact details. It says Muse uses a wallet with Stripe Link at launch (Shop Pay "coming soon") that issues a single-use card tied to one merchant, one amount and a limited time.
BrowserMeta says you can watch and take over, the agent pauses while you do, passwords go straight to secure storage, and classifiers block or prompt for risky forms and suspected prompt injection.

Data and training

Security programme

Meta says it opened its Muse bug bounty to the public, paying up to $300,000 for valid reports, including up to $130,000 for prompt injection that affects one user.

What this does not tell you

Compare with other personal agents in our Instinct vs Muse vs OpenAI dots guide, use the approval checklist, and see the Muse record. Spot an error? Tell us.

Source: Meta AI Research, How We Built Safety Into Muse (8 September 2026).