1. Four tiers of agent permissions

In our library of 22 community use cases, agent interactions span four distinct risk tiers. Do not assume all tasks are passive read-only operations:

TIER 1READ-ONLY ACCESS (DATA INSPECTION)

Used in tasks like auditing 6 months of email receipts or reading Instagram followings.

Important Security Boundary: While read-only scopes cannot delete or modify your accounts, they can still access sensitive personal details (such as billing amounts, home addresses, or travel itineraries). Always redact card numbers before sharing data.
TIER 2OUTBOUND COMMUNICATION (EMAIL & CALLS)

Used when Muse calls customer support (Costco, AT&T, contractors) or drafts dispute emails (Delta flight delays).

Human-in-the-Loop: Never let an agent transmit binding statements or accept price renegotiations without reviewing the transcript or setting a strict maximum authorized rate.
TIER 3ACCOUNT SESSIONS & WEB ACTIONS

Used when Muse logs into carrier accounts (such as United Airlines) or uses browser automation to book parking spots on Groupon.

Session Hygiene: Direct account logins grant broad interface control. Ensure two-factor authentication (2FA) is enabled and monitor active browser sessions.
TIER 4FINANCIAL ORDERS & TRANSACTIONS

Used when delegating grocery purchases on Instacart or moving satoshis via Lightning (Breez).

Spending Caps: Do not grant open-ended wallet authority. Require secondary confirmation for any transaction exceeding your pre-set budget limit.

2. Distinguishing source dates and testing claims

To maintain absolute transparency, AgenScope differentiates between three timeline and audit dimensions:

  • Original Community Post Date: The timestamp when an independent user published their experience on X or Threads (ranging from September 2025 to 2026).
  • Editorial Review Date: The date our editorial team reviewed, sanitized, and cataloged the instructions (September 2025).
  • Independent Testing Status: Unless explicitly labeled Verified by AgenScope, all task guides are classified as Community observation · Unverified in AgenScope sandbox. We do not claim to reproduce closed-beta voice features or proprietary enterprise licenses.

3. Connection methods & authorization

Depending on the task, data reaches Muse through three primary channels:

  1. Manual Chat Paste: You copy text excerpts (e.g. receipt lines, job listings) directly into the prompt. This requires zero account permissions and is the safest approach.
  2. OAuth 2.0 Token Exchange: Supported for third-party platforms (like Gmail or Spotify). Passwords are never shared; temporary access tokens can be revoked at any time.
  3. Integrated Beta Features (Voice Calling & Computer Use): Voice agent calling and browser automation features are in selective beta testing and may not be available on all accounts.

4. How to revoke third-party authorizations immediately

You can sever any connected service at any time:

  1. Open the Muse interface and click on your profile/workspace Settings.
  2. Navigate to Connected Apps & Tools.
  3. Click Revoke Access or Disconnect next to the specific provider.
  4. Source-level cleanup: You can also visit your Google Security, Microsoft Account, or Apple ID dashboard to revoke active OAuth tokens from the provider side.