# Security overview

> Authorization and restriction controls in Cartographer, including security modes, for teams evaluating it before deployment.

UiPath Cartographer is an AI assistant that runs on your work computer. You ask it to do things in plain language, such as "document this process" or "draft the future-state design," and it carries the task out across the applications and systems you already use.

To be useful, Cartographer acts on your behalf. Evaluating its security comes down to two questions: how do you stay in control of what it does, and how does it reach your system? This page answers the first question and summarizes the second. See [Data security and compliance](data-and-compliance.md) for the full data-handling and network detail behind these claims.

## In short

- To do its work, Cartographer sends the content a task needs, including screenshots, to a large language model. Every request passes through the UiPath AI Trust Layer: the connection is encrypted and authenticated service-to-service, and a contractual ban prohibits training with your data. You can also bring your own model, including one hosted locally, in which case the entire data flow stays under your control.
- You control them in two complementary ways: **authorization** (it asks before acting) and **restriction** (hard limits it cannot cross). Both do.
- Every control described on this page and in [Governance with Automation Ops](centralized-configuration.md) can be enforced and locked centrally through UiPath Automation Ops.
- As an individual user, you configure your own approval mode, screen context, execution mode, and the rest of your local security settings — see [Local security configuration](local-security-configuration.md).

## Two kinds of control

| Control | What it means | Where it is configured |
|---|---|---|
| **Authorization** | What approval mode governs. It asks before acting, and can be set per operation (Allow, Ask, Block). Keeps a person in control of *when* it acts. | [Local security configuration](local-security-configuration.md), or centrally through [Governance with Automation Ops](centralized-configuration.md) |
| **Restriction** | Independent of any approval: the operating-system sandbox, blocked paths, blocked apps and sites, disabled tools, credential protection, and automatic redaction. Guarantees that certain things never happen at all. | [Local security configuration](local-security-configuration.md), or centrally through [Governance with Automation Ops](centralized-configuration.md) |

Authorization keeps a person in control of when it acts. Restriction guarantees that certain things never happen at all. Using both together is what makes a regulated deployment safe.

## Approval mode

The most important authorization control is approval mode. It sets how much Cartographer does on its own versus how often it asks you first, and applies to all chats.

| Mode | Runs automatically | Asks your approval for |
|---|---|---|
| **Cautious** | Nothing | Every operation |
| **Adaptive** (recommended) | Read-only actions (read a file, view the screen, list emails) | Any write, change, or execute action, plus any action it judges to be irreversible or high impact (for example, submitting a loan application or making a payment) |
| **Full access** | Everything | Nothing (not recommended outside trusted, thoroughly tested environments) |

In Adaptive mode, reading is free but any change is gated, and Cartographer asks you whenever an action looks irreversible. Entering a password is always an explicit, one-time approval, in every mode.

Approval mode sets the default for the granular, per-tool, per-file, and per-app/site controls in [Security settings reference](security-settings.md) — you can override individual entries there regardless of which mode you have selected. See [Approval mode](local-security-configuration.md#approval-mode) in Local security configuration for the full breakdown.

## Settings storage model

Cartographer separates user-configurable settings from protected permissions into two files: a plain-JSON settings file you can edit directly, and an encrypted file holding tool permissions, Approval Mode, and authentication tokens that's only modifiable through the Settings UI. This design prevents a compromised agent or malicious skill from escalating its own permissions — even if an agent could modify the plain-JSON file, it cannot access or change the encrypted one. See [Settings file locations](settings-file-locations.md) for exact paths and what each file contains.

You can also tune how often Cartographer asks before acting on applications and sites, and block specific destinations or entire sensitive categories outright — see [UI automation](security-settings.md#ui-automation) in Security settings reference.

## Scripting and code execution

When a task needs it, Cartographer can run commands. A command can do anything the signed-in user can do, so this pathway has the strongest controls.

- **Optional kernel sandbox**: Code execution can run inside a kernel-enforced container (Windows AppContainer, or macOS Seatbelt), which confines filesystem and process access, can block network access, and walls off credentials such as SSH keys, cloud credentials, and keychains. It's off by default on new installations. The sandbox is turned on by setting **Terminal & files** to **Restricted access**, in **Settings** → **Security** for chats outside a project, or on a project's **Security** tab for that project.
- **Separate from approval mode**: Approval mode doesn't turn the sandbox on or off. In **Full access** mode, requests to run outside the sandbox are approved without asking, unless **Elevation requests** is set to **Always deny**.

See [Terminal and files](security-settings.md#terminal-and-files) in Security settings reference for the full configuration options.
