Inside Meta’s Muse: Permissions, Tools and Personal AI

Written by
Last updated on:
September 30, 2026
Written by
Last updated on:
September 30, 2026

Meta’s new personal AI agent can send emails, book travel, and make purchases. Its safeguards may be as important as its capabilities.

Meta introduced Muse in September 2026 as a personal AI agent that can work across apps and websites. According to Meta, Muse can send emails, book travel, fill out forms, negotiate on a user’s behalf, and complete purchases after receiving approval. 

Muse initially rolled out in the United States on iOS, Android, and muse.ai. Meta now describes the agent as available in the United States and Canada, with access through the Muse app, WhatsApp, the web, and Mac. Support for Meta’s AI glasses is planned for the coming months.

At Meta Connect, the company also previewed Muse Charm, a pocket-sized device designed for talking and interacting with Muse.

According to Meta, Muse runs on its Muse Spark model inside Muse Secure VM, a dedicated cloud environment with its own browser. The product also includes connected-app permissions, secure credential storage, activity history, and Sentinel, a separate system that Meta says reviews Muse’s actions before they reach the internet.

Muse is a useful test of where personal AI agents are headed. Its capabilities matter, but so do Meta's choices about access, supervision, and accountability when an AI system can operate across the services people use every day.

What Can Muse Do Across Apps and Websites?

Meta positions Muse as a personal AI agent for individual tasks and longer-term goals. A user could ask it to plan a trip, research a purchase, negotiate a bill, or organize a project. Rather than treating each request as a one-off exchange, Muse can continue working on a task and return when it needs clarification or permission.

The product is also intended to retain context from earlier interactions, including a person’s preferences, ongoing goals, or details such as dietary restrictions. Meta’s examples include turning a saved recipe into a grocery list, helping plan a dinner party, or adjusting a training plan when someone’s schedule changes.

That design asks more of the product than a standard AI assistant. Muse needs to identify the steps involved in a task, access the information or service required at each step, and pause when the next action has a meaningful consequence.

For a purchase, that may mean comparing products, checking delivery options, applying a user preference, and asking for approval before checkout. For an email, it may mean retrieving relevant details, preparing a draft, and confirming that the user wants it sent. Meta builds those approval points into the product rather than relying on the model to decide when user confirmation is necessary.

Muse Secure VM, Sentinel, and App Permissions

Muse currently runs inside Muse Secure VM, a dedicated cloud-based virtual machine with its own browser. According to Meta, the environment houses the agent and a user’s data, while securely storing credentials for services the user chooses to connect. This lets Muse work across apps without operating directly inside the user’s device.

Muse works alongside Sentinel, a separate agent that runs on the same machine but is isolated from Muse at the system level. According to Meta, nothing Muse does reaches the internet unless Sentinel approves it, and Sentinel asks the user for permission when needed.

Meta says Muse can’t see a user’s passwords or payment details. Instead, connected credentials are stored separately, allowing the agent to use a service without accessing the underlying login or payment information. For checkout, Muse can use Link by Stripe to create a one-time-use card rather than expose a user’s actual card number. Meta has also announced planned support for Shop Pay and 1Password.

Users can determine which services Muse may access and what it can do within each one. For example, someone could allow Muse to read email without letting it send messages. They can also disconnect a service, revise access settings, review an activity record, or ask Muse to forget retained information. 

Meta also says users can opt out of having their Muse interactions used to train Meta’s AI models. The company says it doesn’t share Muse conversations or data stored in a user’s VM with its advertising systems.

These safeguards don’t eliminate every risk, however. Meta acknowledges that Muse can make mistakes and that prompt injection remains an open problem. The current VM architecture also doesn’t prevent Meta from accessing stored information when needed to support, secure, or operate the service. Meta says a planned Confidential VM is intended to provide that stronger separation.

Where Permissions and Approval Fit In

Muse began as a consumer product, and Meta has since expanded it with connectors and skills for small businesses. Its design reflects a broader challenge for any agentic system: the agent needs enough access to complete useful work without receiving unrestricted authority.

That distinction becomes clearer when an agent’s abilities are separated by the type of action involved. It might retrieve an order record without changing it, prepare a response without sending it, or recommend a resolution without issuing a refund. Each step calls for a different level of access and human review.

For example, a customer-support agent could retrieve an order record, identify the relevant return policy, and prepare a response for an employee to review. A sales agent could draft follow-up notes from approved CRM and product information. An operations agent could assemble a work order while leaving a supervisor responsible for scheduling changes or equipment requests.

Production workflows usually need:

  • Read access to approved systems and documents
  • Task-specific access to tools and data
  • Approval steps for actions involving customers, money, operations, or sensitive information
  • Activity records showing what the agent retrieved, recommended, and attempted
  • A clear handoff when the agent lacks information, encounters a tool failure, or reaches a decision it is not authorized to make

Activity records are particularly important once an agent can work across business tools or customer data. Teams need to investigate inaccurate outputs, understand the information and actions that led to a result, and update the workflow when policies, systems, or edge cases change.

Need help building ethical and scalable AI systems? Read our guide here.

Muse vs. Muse Glimmer: What’s Different?

Muse and Muse Glimmer are related releases, but they serve different purposes.

Muse is a managed personal AI agent powered by Meta’s proprietary Muse Spark model. It is designed to complete tasks across connected apps and websites, using Meta’s hosted environment, browser, permission controls, credential handling, approval prompts, and activity history.

Muse Glimmer is an open-weight model for developers building their own tool-using agents. Teams can run it locally, fine-tune it for a specific use case, and connect it to internal systems and data sources.

Muse is aimed at individuals who want a ready-to-use agent that operates in Meta’s hosted environment. Muse Glimmer is aimed at developers and organizations that want to run and adapt a model within their own systems. With Glimmer, the team deploying it is responsible for the surrounding controls: deciding where it runs, which data and tools it can access, what actions require approval, and how activity is monitored and logged.

Employee walking through a bright Meta office atrium with colorful geometric window artwork, white railings, and open interior levels. Image courtesy of Meta, 2026.

From Demos to Workflows

Muse provides a useful reference point for teams considering agents in customer support, sales, operations, engineering, or internal knowledge management. The product is designed around consumer tasks, but the implementation questions are familiar across industries.

Before connecting an agent to enterprise systems, teams should define:

  • The workflow the agent will support
  • The systems, tools, and information it needs
  • The minimum level of access required
  • The actions that require employee, customer, or administrator approval
  • The information that must be logged for review and troubleshooting
  • The fallback process for incomplete data, conflicting instructions, or failed tool calls

The workflow should shape the architecture. A knowledge assistant may only need read access to approved documentation. A customer-service agent may need to retrieve account information and propose a resolution, while an employee retains the authority to issue a refund. An agent that changes inventory, creates a purchase order, or modifies a production schedule needs stronger controls, clearer review points, and more detailed activity logging.

Teams also need to test agents against the environment where they will actually operate. That includes incomplete records, ambiguous requests, permission errors, tool failures, and attempts to direct the agent outside its approved role. A polished demonstration does not show whether an agent will behave reliably across the edge cases that emerge in a production workflow.

Building Agentic Systems for Production

Meta’s Muse combines a model, a secure execution environment, connected applications, permission settings, credential controls, approval prompts, and activity history. Each part supports a different aspect of the work Muse is designed to perform.

For organizations building AI agents, the starting point isn’t broad access to every available system, but instead a clear understanding of the task, the tools required, the decisions an agent can make, and the situations where people need to remain involved.

FullStack helps organizations build AI and agentic systems around real workflows. Our teams support product strategy, software development, enterprise integrations, data controls, evaluation, and production deployment. 

Explore our AI and agentic solutions to learn how we can help your team build reliable AI-enabled products.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Get the guide

Learn more

Frequently Asked Questions

Meta Muse is a personal AI agent designed to work across connected apps and websites. According to Meta, it can help with tasks such as sending emails, researching purchases, booking travel, filling out forms, negotiating bills, and completing purchases after receiving approval.

Muse lets users choose which services it can access and what it can do in each one. A user could allow the agent to read email without allowing it to send messages, for example, while actions involving purchases, sensitive information, or other meaningful consequences can require approval.

Muse Secure VM is Meta’s cloud-based virtual machine for running the Muse agent and its browser. Meta says the environment stores connected-service credentials separately from the agent, allowing Muse to use approved services without directly accessing a user’s passwords or payment information.

Sentinel is a separate control system that reviews Muse’s actions before they reach the internet. According to Meta, Sentinel acts as the permission authority for connected services and network activity, deciding whether to allow an action, deny it, or request the user’s approval.

Meta Muse is a managed personal AI agent for individuals, operating in Meta’s hosted environment with built-in permissions, credential controls, approval prompts, and activity history. Muse Glimmer is an open-weight model for developers and organizations building their own tool-using AI agents, meaning the deploying team is responsible for access controls, approvals, monitoring, and logging.