DATA BOUNDARY
Execution stays here. The boundary is documented.
The local runtime owns browser control, sessions, flows and evidence. Normal traffic reaches the application under test; model context crosses a separate boundary only when explicitly configured.
- Local control plane
- Explicit model egress
- No zero-network claim
EGRESS RECEIPT
Two boundaries. Each one named.
-
01
Browser → tested application
-
02
Local session and credentials
-
03
Optional bounded model context
-
04
Evidence remains on machine
Boundary modes
01 · DEFAULT
Run without a model. Keep the control plane local.
Record, replay, assert and preserve redacted evidence without configuring an AI provider.
The application under test
The browser sends the normal traffic required to exercise the authorized site.
No model configuredSessions, flows and evidence
Browser control, credential references and run artifacts remain on the Mac.
Desktop runtime owns execution02 · SELECTED STEP
Choose one model boundary. Keep it visible.
A selected AI step may send a masked instruction, sanitized page identity, bounded visible text and semantic candidates through the provider key the operator configures.
Bounded and masked
The selected step receives only the context needed for its declared task.
No screenshot sent for this modeYour provider relationship
The configured key and provider billing remain under the operator’s control.
Explicit runtime choice03 · INTEGRATED AGENT
Fix the origin first. Approve consequential actions.
During integrated authoring, the configured model receives bounded, redacted page context and can choose only among current controls in the authorized origin.
Encrypted local references
The runtime fills credential values locally rather than placing them into the authoring prompt.
Browser control remains localAn ordinary saved flow
Approved actions become deterministic RERUN steps that can be reviewed and replayed later.
Model not required for replay