On your own machine
What it is like to hand over the keyboard
Handing over the keyboard is the part that needs the most safeguards, and this section covers them. You approve, you watch, and you can stop it mid-step.
- It gets the keyboard, the mouse and the screen
- Not a browser script and not an API wrapper. The agent works your applications the way a person does. That is why it reaches software that was never on the web to begin with, including the in-house system nobody is ever going to replace.
- An approval card in front of the action
- Each action is described before it happens: what it is about to click, type or run. You approve, or you don't. There is an auto-accept mode for the safe ones, and it is deliberately narrow. Reading a file full of credentials still comes back to you, because that is the one read nobody can undo.
- It cannot act on a stale look at the screen
- If the window moved since the agent last looked, the click is refused, and the refusal names the window that is in front now. Guessing here is how automation types a password into the wrong box.
- You can stop it mid-step
- Stop means stop: the request is aborted, the machine is handed back, and the run is recorded as stopped rather than quietly finished.
- Several conversations, one machine
- Only one run can hold the screen at a time, so a second run reaching for the keyboard waits and says so, instead of fighting over the mouse. Work that does not need the screen carries on beside it: a build, a file, a spreadsheet.
- It can show you the file, not just describe it
- A spreadsheet as a real grid, a document as pages, a deck as slides, a PDF, an image, all beside the chat. The agent can point at the exact row or heading it means. It can also browse a real website in the same pane, signed in as you, without taking over your screen.
Steptree refuses instead of deploying blind
Anyone can build a cloud agent and let it fail on the first screen it cannot see. Steptree analyses the approved procedure, and when a step needs a desktop it refuses the cloud deployment and names the skill and the step. Knowing in advance what it will refuse is what lets you plan around it.