An assistant with access to your computer needs a boundary you can see and control. In ModulawAI for Desktop nothing local runs until you switch it on, what you switch on expires by itself, and one button stops everything mid-task.
Where the controls are
Open Case Manager, then Integrations. The desktop panel there shows whether the app is connected, which capabilities are on, and the stop button.
What each capability allows
| Capability | What it allows | Also needs |
|---|---|---|
| Files | Reading and writing inside folders you have nominated | An approved folder |
| Local tools | Browser automation and other local servers bundled with the app | — |
| Computer use | Seeing your screen and operating applications — clicking, typing, navigating | Screen Recording and Accessibility |
| Shell | Running commands on your machine | — |
Switch on only what the work in front of you needs. There is no benefit to enabling all of them, and a narrower boundary is easier to reason about.
They expire after an hour
Anything you switch on turns itself off one hour later. This is deliberate: a permission you granted on Monday for one task should not still be live on Friday.
In practice this means a long session can stop part-way through, and the assistant will begin reporting that it cannot act. That is not a fault. Switch the capability on again and carry on. The panel shows when the current window ends.
Stopping everything
The stop control in the same panel halts local activity immediately and switches every capability off. Use it if the assistant is doing something you did not intend, or if you simply want to put the machine beyond reach while you step away. Nothing local can run again until you switch something back on.
What still stops and asks
Switching a capability on is not a blank cheque. Actions that cannot be undone — deleting, moving files, force-pushing, sending data out — pause and ask you to confirm, every time, even while the capability is on.
A smaller set of operations is never permitted: erasing a disk, wiping a home directory, overwriting a device. These are refused outright. Switching a capability on does not enable them, and confirming does not either.
Computer use is treated slightly differently. It is not practical to confirm every individual click while the assistant works through a task, so the boundary is drawn elsewhere: the macOS permissions, a cap on how many steps one task may take, a check that halts if instructions appear to be coming from something on screen rather than from you, and the stop button. You watch it work, and you can end it at any point.
Files: nominating folders
File access is confined to folders you approve. A path outside them is refused — not merely discouraged — so the assistant cannot reach the rest of your disk even if asked to.
Choose the narrowest folder that does the job. A single matter folder is better than your whole home directory, and switching later is easy.
Everything is recorded
Each decision — what was requested, whether it was allowed, whether you confirmed it, what ran — is written to a log on your own machine. It stays local, and it is there when you need to account for what the assistant did.
If something will not run
| Message | What to do |
|---|---|
| The capability is not switched on | Switch it on in Case Manager → Integrations |
| It worked and has stopped | The hour has elapsed. Switch it on again. |
| Cannot see the screen | Grant Screen Recording and restart the app — see Granting macOS permissions |
| Path is outside the approved folders | Add that folder, or ask for something inside one you have already approved |
| No desktop app is connected | The desktop app is not running or not signed in. This is not a permissions problem — open the app and sign in. |