# Local security configuration

> Security controls an individual user sets directly from the chatbox — approval mode, screen context, and execution mode — plus OS-level permissions and advanced security settings.

This page covers the security controls you set yourself, as an individual user, starting with the three controls available directly from the chatbox.

## Security checklist

These are the main tasks to configure Cartographer locally, in order:

- Set [approval mode](#approval-mode) from the chatbox
- Review [computer use settings](#computer-use-settings) — Cartographer uses Guarded mode instead of screen context or execution mode
- Review [advanced security settings](#advanced-security-settings) — fine-grained Allow/Ask/Block control over tools, terminal and files, protected files, and UI automation
- Choose your [conversation storage](#conversation-storage) mode
- Verify [OS-level permissions](#os-level-permissions)
- Review installed skills' requirements against your setup for compatibility
- Know how to interrupt or stop Cartographer (Escape key)

## Approval mode

Set from the mode selector next to the chatbox, and applies to all chats.

| Mode | Behavior |
|---|---|
| **Cautious** | Asks for all operations; strict process isolation with allowlist-only access |
| **Adaptive** (recommended) | Runs safe tools automatically; asks before high-impact operations; protects credentials and sensitive files |
| **Full access** | Full system access, no prompts |

Approval mode sets the defaults for the granular, per-tool, per-file, and per-app/site controls — tool permissions, terminal and files, protected files, and UI automation — described in [Security settings reference](security-settings.md).

## Computer use settings

:::note
Cartographer doesn't provide screen context or execution mode — it doesn't drive your screen directly. Instead, while you're inside a business process, the chat box shows a **Guarded mode** toggle (off by default) that restricts Cartographer to the files and folders listed in the Allowlist tab of Project settings. See [Model and behavior settings](your-first-cartographer-tasks.md#model-and-behavior-settings) in Your first Cartographer tasks for details.
:::

## Advanced security settings

Beyond approval mode, **Settings** → **Security** holds four areas of fine-grained, per-tool, per-file, and per-app/site controls:

| Area | Covers |
|---|---|
| **Tool permissions** | Allow, Ask, or Block for individual tools, connectors, and operations |
| **Terminal and files** | The shell command sandbox, its allowed paths, capabilities, and blocked commands |
| **Protected files** | Files Cartographer needs approval to access — secrets, keys, cloud credentials, config, and data files |
| **UI automation** | Trusted and blocked apps and websites |

See [Security settings reference](security-settings.md) for the full breakdown of each.

## Conversation storage

A user-selectable, security-relevant setting that lives outside Settings → Security: **New tasks**, under [Settings → General](general-settings.md) → **General**.

| Mode | Behavior |
|---|---|
| **Local** | Chat history stays on the device only (SQLite). |
| **Remote** | A PostgreSQL database stores chat session metadata, message content, delegation requests, user settings, daily usage, and product settings. |

Message content, including attachments and screen context screenshots, transits the UiPath backend for inference regardless of storage mode, but is not persisted server-side in Local mode.

## OS-level permissions

Beyond approval mode, screen context, and execution mode, the operating system controls what Cartographer can do — and always takes precedence: if Windows denies a permission, it cannot do that thing regardless of what you have set above.

The following table lists the permissions Cartographer requires on Windows.

| Permission | Where to Grant | What It Enables |
|------------|----------------|-----------------|
| **UI Automation** | User Account Control during install | Controlling applications |
| **File System** | Standard user permissions | Reading/writing files in accessible locations |
| **Network** | Windows Firewall (if prompted) | Web access, cloud integrations |

:::note
Running as Administrator grants broader access but is not required for normal operation, and prevents them from driving applications you have launched as administrator.
:::
