Cover: AI-generated editorial composition by TMRW, based on Meta’s Muse design imagery. Source material.
Meta introduced Muse on September 8 with a proposition that is easy to understand: give an agent a task, let it use your apps, and come back to completed work. The launch puts a personal agent inside WhatsApp as well as a dedicated app. The important question is what happens between your request and an action taken in your name. Meta's announcement describes email, travel bookings and longer-running goals as intended uses.
That moves the decision beyond whether you like an assistant's answers. Reading a calendar, changing a meeting and paying for a flight require different amounts of trust. Muse's launch is interesting because Meta has published details about how those differences are enforced.
A personal computer behind the conversation
According to the product team's design account, Muse has a browser, terminal and filesystem. It can build documents and small interactive tools, continue work on a schedule, and show an activity log. The team also describes side conversations for projects and notifications intended to surface meaningful developments rather than every background step.
Those choices address a practical problem with delegation: once work continues after you close a conversation, the transcript stops being a sufficient record. You need to see what happened, which permissions made it possible, and where to intervene. A useful test would be a mundane task with a verifiable finish, such as finding calendar conflicts. An impressive conversation tells you much less.
The permission system is part of the product
Meta's technical account separates the agent's working environment from credential storage and a permission authority called Sentinel. The agent requests actions; Sentinel decides whether to allow them, reject them or ask the user. Meta says real credentials are inserted only at the authorized point of use.
The same account describes approvals tied to particular actions or scopes, and a human approval for purchases. It also says the virtual machine sends limited information outside itself for inference and telemetry. A dedicated VM therefore should not be read as a promise that all processing stays inside that machine. These are Meta's descriptions of its controls, not an independent security audit.
What to check before handing over a task
Our suggested first session would test three things. Can you grant only the access the job needs? Can you understand the proposed action before approving it? Can you find a useful record afterward? Ask for a result you can check in the original app, then compare it with the activity log.
For example, identifying an available dinner slot and actually booking a table are separate milestones. A good delegation flow should make that transition obvious. If the agent has misunderstood the date or party size, the right moment to discover it is before the reservation.
We have reviewed the launch, design and security documents, rather than completed a hands-on reliability test. Our assessment is that Muse makes permissions and visibility central to the consumer-agent competition. The launch establishes what Meta intends to deliver. Repeated, inspectable task completion will establish whether people should depend on it.



