- Overview
- Installation and setup
- Getting started
- Trust and compliance
- Governance
- Features
- Delegate for Testing
- Reference
- Troubleshooting
- Backup and restore
Local security configuration
Security controls an individual user sets directly from the chatbox — approval mode, screen context, and execution mode — plus OS-level permissions and advanced security settings.
This page covers the security controls you set yourself, as an individual user, starting with the three controls available directly from the chatbox.
Security checklist
These are the main tasks to configure Delegate locally, in order:
- Set approval mode, screen context, and execution mode from the chatbox
- Review Restricted access if you need to scope Delegate to specific folders
- Review advanced security settings — fine-grained Allow/Ask/Block control over tools, terminal and files, protected files, UI automation, and Restricted access
- Choose your conversation storage mode
- Verify OS-level permissions
- Review installed skills' requirements against your setup for compatibility
- Know how to interrupt or stop Delegate (Escape key)
Approval mode
Set from the mode selector next to the chatbox, and applies to all chats.
| Mode | Behavior |
|---|---|
| Cautious | Asks for all operations; strict process isolation with allowlist-only access |
| Adaptive (recommended) | Runs safe tools automatically; asks before high-impact operations; protects credentials and sensitive files |
| Full access | Full system access, no prompts |
Approval mode sets the defaults for the granular, per-tool, per-file, and per-app/site controls — tool permissions, terminal and files, protected files, and UI automation — described in Security settings reference.
A shell command waiting for approval shows its approval card with the agent's steps above the exact script, so you can see why it wants to run the command before you approve it.
Computer use settings
Screen context and execution mode both govern computer use for Delegate — what it can see, and how it acts on your screen.
Execution mode
Governs how it acts — whether it takes over your screen or works without touching it. Set from the computer icon next to the chatbox:
| Mode | Behavior |
|---|---|
| On my screen | Drives your mouse and keyboard on the current screen |
| Ask before each app | Asks for approval before taking the first action in each application |
| In the background | Works without taking over your screen |
In the background expands into three sub-modes:
| Sub-mode | Behavior |
|---|---|
| Native Background | Runs web and desktop tasks together in the background |
| Web only | Runs browser tasks in a minimized window via CDP — suitable for parallel browser work |
| Local (new session) | Creates a separate Windows session via RDP — setup is required |
Screen context
Governs what it can see. Set from the screen icon next to the chatbox:
| Option | What it sees |
|---|---|
| Default | Only the apps attached to the current chat |
| All apps | Every visible app |
| None | Nothing — it can ask you to turn it on when it needs to |
The chatbox also shows which apps are currently attached to the chat, since it only sees what's listed there when capturing your screen.
First message of each turn
A related setting under Settings → General → General.
In Default mode, each user message gets one full-screen capture so "do this for me" works on cold start. Subsequent turns within the turn mask to attached apps. On by default.
Restricted access
A toggle (off by default) that scopes Delegate to an allowed set of folders, blocked paths, and approval exceptions. The same panel is shared between Settings → Security → Restricted access and the Security tab of each project's own Project settings — changes made in one are reflected in the other.
Advanced security settings
Beyond approval mode, Settings → Security holds five areas of fine-grained, per-tool, per-file, and per-app/site controls:
| Area | Covers |
|---|---|
| Tool permissions | Allow, Ask, or Block for individual tools, connectors, and operations |
| Terminal and files | The shell command sandbox, its allowed paths, capabilities, and blocked commands |
| Protected files | Files Delegate needs approval to access — secrets, keys, cloud credentials, config, and data files |
| UI automation | Trusted and blocked apps and websites |
| Restricted access | Folders, blocked paths, and approval exceptions, shared with each project's own Security panel |
See Security settings reference for the full breakdown of each.
Conversation storage
A user-selectable, security-relevant setting that lives outside Settings → Security: New tasks, under Settings → General → General.
| Mode | Behavior |
|---|---|
| Local | Chat history stays on the device only (SQLite). |
| Remote | A PostgreSQL database stores chat session metadata, message content, delegation requests, user settings, daily usage, and product settings. |
Message content, including attachments and screen context screenshots, transits the UiPath backend for inference regardless of storage mode, but is not persisted server-side in Local mode.
OS-level permissions
Beyond approval mode, screen context, and execution mode, the operating system controls what Delegate can do — and always takes precedence: if macOS or Windows denies a permission, it cannot do that thing regardless of what you have set above.
The following table lists the permissions Delegate can use on macOS. All are optional; you can check their status in Settings → Permissions. That page also lists Accessibility as required, but Delegate doesn't use it.
| Permission | Where to grant | What it enables |
|---|---|---|
| Screen Recording | System Settings → Privacy & Security → Screen & System Audio Recording (Screen Recording on macOS 14) | Recording a task you show it, screen included |
| Full Disk Access | System Settings → Privacy & Security → Full Disk Access | Opening files anywhere on your Mac without being asked for each folder |
| Microphone | macOS asks the first time; you can change it later in System Settings → Privacy & Security → Microphone | Spoken descriptions and audio transcription |
On Windows, Delegate doesn't need any permissions. If spoken input doesn't work, check that microphone access for desktop apps is on in Windows Settings → Privacy & security → Microphone.
On Windows, running Delegate as Administrator grants broader access but is not required for normal operation. If Delegate isn't running as Administrator, it can't drive applications that you launched as Administrator.