---
name: "Draft-first Auto-review + takeover; Bots are not a security boundary"
description: "Use when every consequential move needs draft-first Auto-review; Bots are not a security boundary."
---

# Draft-first Auto-review + takeover; Bots are not a security boundary

## When
Use when setting stop lines for send, pay, deploy, delete, and Auto-review rules.

## Stop
Always require approval for send/invite, publish, purchase, delete/overwrite, permission changes, production, legal terms. Never allow everything in the browser. Never paste passwords into chat.

## Steps
1. Put the stop in the request: `Reconcile the campaign data and draft a recommended budget change. Do not change the campaign or message the agency. Ask for approval after showing the current value, proposed value, and expected impact.`
2. Always require approval for: send/invite, publish, purchase, delete/overwrite, permission changes, production, accepting legal terms.
3. Settings → General → Auto-review. Narrow rules only. Require Approval always wins over Always Allow. Example: require approval before any external email; always allow `git status` in `/workspace/reports`. Never “allow everything in the browser.”
4. Passwords/2FA/CAPTCHA/payment: Agent Computer → take control → finish the blocked step → continue. Masked secret request when offered. Never in chat.
5. Local Mac/Windows execution is separate: Settings → General → Agent → Execution on Local Computer. Default Ask every time. Set Never allowed unless a Bot must touch local files. This does not restrict the cloud computer.
6. Offboarding order: pause/delete routines → sign out of sites → uninstall connectors and revoke in the source → delete sensitive `/workspace` files → hide/delete Bots. Deleting a Bot does not wipe shared files or sessions.

## Load
Settings → Auto-review. Takeover for 2FA/pay. Least privilege on plugins.
