Privacy & control / Planning guide
Give access with intention
The boundaries the new agent must preserve.
Embla is in development. This describes the intended experience, not instructions for a shipped device.
Use an unprivileged account
The agent should run as a dedicated Linux user. Administrative changes should require explicit local elevation.
Scope connected services
Each integration should expose only the accounts, folders, and capabilities the owner intentionally enables.
Make sensitive actions visible
Sending, purchasing, deleting, publishing, and changing security settings need understandable approval boundaries.
Verify the implementation
These are requirements for the new build, not claims about currently available agent software.