# Local security configuration

> Security controls an individual user sets directly from the chatbox — approval mode, screen context, and execution mode — plus OS-level permissions and advanced security settings.

This page covers the security controls you set yourself, as an individual user, starting with the three controls available directly from the chatbox.

## Security checklist

These are the main tasks to configure Cartographer locally, in order:

- Set [approval mode](#approval-mode) from the chatbox
- Review [computer use settings](#computer-use-settings) — Cartographer uses Guarded mode instead of screen context or execution mode
- Review [advanced security settings](#advanced-security-settings) — fine-grained Allow/Ask/Block control over tools, terminal and files, protected files, and UI automation
- Choose your [conversation storage](#conversation-storage) mode
- Verify [OS-level permissions](#os-level-permissions)
- Review installed skills' requirements against your setup for compatibility
- Know how to interrupt or stop Cartographer (Escape key)

## Approval mode

Set from the mode selector next to the chatbox, and applies to all chats.

| Mode | Behavior |
|---|---|
| **Cautious** | Asks for all operations; strict process isolation with allowlist-only access |
| **Adaptive** (recommended) | Runs safe tools automatically; asks before high-impact operations; protects credentials and sensitive files |
| **Full access** | Full system access, no prompts |

Approval mode sets the defaults for the granular, per-tool, per-file, and per-app/site controls — tool permissions, terminal and files, protected files, and UI automation — described in [Security settings reference](security-settings.md).

## Computer use settings

:::note
Cartographer doesn't provide screen context or execution mode — it doesn't drive your screen directly. Instead, while you're inside a business process, the chat box shows a **Guarded mode** toggle (off by default) that restricts Cartographer to the files and folders listed in the Allowlist tab of Project settings. See [Model and behavior settings](your-first-cartographer-tasks.md#model-and-behavior-settings) in Your first Cartographer tasks for details.
:::

## Advanced security settings

Beyond approval mode, **Settings** → **Security** holds four areas of fine-grained, per-tool, per-file, and per-app/site controls:

| Area | Covers |
|---|---|
| **Tool permissions** | Allow, Ask, or Block for individual tools, connectors, and operations |
| **Terminal and files** | The shell command sandbox, its allowed paths, capabilities, and blocked commands |
| **Protected files** | Files Cartographer needs approval to access — secrets, keys, cloud credentials, config, and data files |
| **UI automation** | Trusted and blocked apps and websites |

See [Security settings reference](security-settings.md) for the full breakdown of each.

## Conversation storage

A user-selectable, security-relevant setting that lives outside Settings → Security: **New tasks**, under [Settings → General](general-settings.md) → **General**.

| Mode | Behavior |
|---|---|
| **Local** | Chat history stays on the device only (SQLite). |
| **Remote** | A PostgreSQL database stores chat session metadata, message content, delegation requests, user settings, daily usage, and product settings. |

Message content, including attachments and screen context screenshots, transits the UiPath backend for inference regardless of storage mode, but is not persisted server-side in Local mode.

## OS-level permissions

Beyond approval mode and your security settings, the operating system controls what Cartographer can do — and always takes precedence: if macOS or Windows denies a permission, Cartographer can't do that thing regardless of what you have set above.

The following table lists the permissions Cartographer can use on macOS. All are optional; you can check their status in **Settings** → **Permissions**. That page also lists Accessibility as required, but Cartographer doesn't use it.

| Permission | Where to grant | What it enables |
|---|---|---|
| **Screen Recording** | System Settings → Privacy & Security → Screen & System Audio Recording (Screen Recording on macOS 14) | Recording a task you show it, screen included |
| **Full Disk Access** | System Settings → Privacy & Security → Full Disk Access | Opening files anywhere on your Mac without being asked for each folder |
| **Microphone** | macOS asks the first time; you can change it later in System Settings → Privacy & Security → Microphone | Spoken descriptions and audio transcription |

On Windows, Cartographer doesn't need any permissions. If spoken input doesn't work, check that microphone access for desktop apps is on in Windows Settings → Privacy & security → Microphone.

:::note
On Windows, running Cartographer as Administrator grants broader access but is not required for normal operation. If Cartographer isn't running as Administrator, it can't drive applications that you launched as Administrator.
:::
