Is Meta Muse Safe? Permissions, Approvals, and What Each Connector Can See
Last updated: October 6, 2026
"Is Meta Muse safe?" packs a few questions into one. What can it see, and what can it do without asking? Short version on privacy: the architecture is sound and the defaults are reasonable. The failure modes are specific, and you can avoid them.
For the full connector list, see the Meta Muse connector directory.
How Meta Muse permissions work
Connectors are the apps you link to Muse: Gmail, Calendar, Notion, Plaid, Spotify, dozens more. Connect one in Settings → Connectors, or ask in chat ("Connect my Gmail").
- Your password stays with the app. Connections go through each app's own login flow.
- Read and write stay separate. Many connectors offer a read-only mode.
- Approval is the default. Out of the box, Muse asks before doing anything important.
- You can pull the plug anytime. Disconnecting in Settings stops the data flow immediately.
- Custom connectors are the wild west. Meta states plainly that it doesn't review custom connectors.
What each connector can see
"Can Muse see my emails?" Yes, once you connect Gmail and grant access. Email search stays scoped to what the task needs. The practical risk sits one level up: an agent holding your email, calendar, and bank link in one place has a wider blast radius than any single app.
Payments get the strongest isolation. Checkout runs through wallets like Link by Stripe, Shop Pay, or PayPal, and it still needs your approval first.
The incidents, honestly
Muse launched September 8, 2026. Within two weeks, four stories tested every claim above. Read them before granting broad access.
- The Marketplace address (late September). A standing permission led Muse to send a buyer a seller's pickup address.
- The Messages dispute (September 23–30). Reporting and Meta's response remain irreconcilable.
- The Amazon block (September 20). Amazon began blocking Muse from shopping on Amazon.com.
- The zero-day (September 21). A Mac setting could redirect voice input; Meta shipped a hot fix.
How to lock it down
- Start read-only. Add write permissions after you've watched the agent behave.
- Set approvals to "Always ask" in Settings → Permissions.
- Keep sensitive details out of standing instructions.
- Audit and prune. Open Settings → Connectors every few weeks.
- Keep Mac Full Disk Access off unless you want Messages integration.
Where this is going
On October 6, 2026, Sierra and Meta unveiled the Personal Agent Protocol, an open standard backed by Walmart, Stripe, Shopify, Instinct, Genesys, and Rocket. It lets businesses tell when they're dealing with a personal agent and set limits on what it may do.
Permissions are heading toward verifiable delegation with clear scopes. That future doesn't change what you should do today.
Bottom line
Muse's permission model improves on what came before it, with OAuth replacing pasted passwords, approval gates on irreversible actions, an audit trail, and credentials the agent can't see. September's failure modes were real all the same.
Practical rule: start with read-only errands and tight approvals, and never hand "Allow Always" to anything that messages strangers or moves money.