Home / On your machine

You run an assistant on your own machine. What can it reach, and what on it matters?

Four steps, ten prompts, the same sequence as the other two walkthroughs. In the browser, host means the vendor's environment. On your machine it means your machine: the home directory with credentials in it, the folder that is the work, the folder that is somebody else's, and every past conversation the application kept. The agent cannot tell which of those matters. Step two is where you say.

Start here if you only do one thing. Open the desktop assistant and paste the first prompt. It lists what is switched on right now, which is usually more than was switched on when you installed it.

What the published shape says

This site holds a derived profile for a desktop application with local tools: 10 of 23 capability primitives, none measured on an instance. 4 of its rows sit at a setting, the third barrier kind: a switch the account running the application can flip. That is the shape's whole character. Reading your files, changing them and running commands are each one switch away, and the switch is yours.

CapabilityUndoBarrierKnown by
authenticate-as.credential.tenant Act in accounts with the credentials it holdsnonone (not a control)derived
read.credential.host Read credentials stored where it runsnonone (not a control)documented
read.record.history Read a retained record: shell history, past sessionsnonone (not a control)documented
send.endpoint.world Reach any host on the internetnonone (not a control)derived
read.file.host Read any file the account can reachnosetting (not a control)derived
write.file.project Change the project it is working onwith-effortnone (not a control)derived
execute.process.host Run programs as the accountwith-effortsetting (not a control)derived
write.file.host Change any file the account can reachwith-effortsetting (not a control)derived
read.file.project Read the project it is working onyesnone (not a control)derived
grant.credential.self Change its own permission settingsyessetting (not a control)derived

Two rows have no switch at all. read.record.history, the past conversations the application keeps, and read.credential.host, the credentials a home directory holds, are documented as reachable with nothing in the way. If your past conversations contain secrets, those two rows are one row.

The concept this walkthrough is built on

What you are giving the agent is context on what is important and what is not. A permission says what is possible. A rule says what is forbidden. Neither says that the folder called work is the work, that the folder called clients is other people's, that the file in the home directory with the token in it must never be opened, or that the unread conversation from last month is the one with the password in it. An agent that has the map decides better on its own; one without it decides by guessing, and guesses reasonably, which is the problem.

LayerWho owns itWhat it says
What the application can dothe vendorlocal files, commands, connectors, the record, each behind a switch or not
What is switched onyou, one click at a timethe settings as they stand today, which is the union of everything you ever enabled
What matters on the machineyou, and nobody else can write itthe work, the not-yours, the credentials, the record
What your organisation requiresyour organisationwhose material is on the machine, and what may leave it

The four steps

Step 1: What it can reach on your machine

Have the agent list its local tools, its connectors, and whether it can read past conversations, and say which of those are switched on right now.

about five minutes

Step 2: What matters, and what does not

Give it the map: the folder that is the work, the folders that are not yours to touch, where the credentials live, and what in the record must never be reused.

about five minutes

Step 3: Write the rules

Turn the map into a document the agent can decide against: what it may reach freely, what it asks about, what it never touches, and the report at the end of every turn.

about five minutes

Step 4: What a switch is, and is not

Four of the shape's rows sit at a setting you can flip. Why that is not a control, and what on a machine actually is one.

about five minutes

What you will have at the end

Where the numbers on this page come from. The published profile for anthropic/claude-desktop/default, which is derived and not measured: 0 of 11 rows were seen on an instance, and the rest were read from what a desktop application running as a user account architecturally is. Your deployment is not that one; the prompts on this page produce yours. The rows, the profile as JSON.
Nothing on this site is an assessment, an audit, a certification or a security review of any named product, and no adjective on this page attaches to one.

Your mailbox · The cost ABP · The four barriers · A case with three surfaces of one product