Skip to content

Your limits

The parameters are the product

Every limit below is on by default. You can loosen any of them, and you can add sites the agent must never open or act on — your bank, your work email, anything you like.

Never spend money without asking

Any checkout, payment or subscription stops and waits for you. Set a spend limit and anything above it is refused outright.

Never send anything in your name

Emails, messages, form submissions and posts are shown to you in full before they go.

Never enter passwords or codes

The agent will not type a password, card number or one-time code. It hands the keyboard back to you.

Never delete or cancel

Deleting, unsubscribing, cancelling and archiving are refused.

Never download or run files

No files are saved or opened on your machine by the agent.

Choose how often it asks

By default agents run without asking. You can switch to approving only the risky steps or every step. The hard limits apply in all three.

Honest limits

What Sentinel cannot promise

An agent that reads web pages can be fooled by web pages. That is the state of this technology in 2026, and it is exactly why the hard limits exist.

  • Hidden instructions on a page can mislead the agent about what it is doing. Sentinel checks the action it is about to take, which catches the consequences — but it does not make the agent immune to being misled.
  • Agentic browsers have been shown completing purchases on fake shops and leaking a one-time code read off a page. We design for that happening, not against admitting it.
  • Sentinel cannot undo something irreversible that has already completed. That is why spending, sending and deleting stop before they happen rather than after.
  • It protects what passes through it. An agent you run outside Sentinel, in your own browser, is not covered.
  • It does not score risk or predict behaviour. It applies rules you can read and change.
Download Sentinel