1. Your OK, every time
Anything that writes, sends, moves money or changes something, your agent shows you first and waits for you to say yes. It shows you exactly what it’s going to do (who it’s writing to and the text, how much money and where to, what event it’s creating) with buttons like these:- Send / Change: an email or a message.
- Issue / Change: an ARCA invoice.
- Confirm / Change: everything else (a transfer, an event, a change).
2. Each plugin’s switches
Some plugins have an extra permission that comes turned off. While it’s off, the agent can’t do that, even if you ask it to.
You turn it on from the agent’s page → Plugins tab → the plugin’s card.

- Only you can change them. The agent can’t, and if it tries, minai doesn’t let it.
- When you change one, the agent is told.
- Even when it’s on, every action still needs your OK.
For the money and email plugins (Email, ICBC, Mercado Pago, ARCA, Stripe), the permission is enforced on minai’s servers: it doesn’t depend on the agent “behaving”. For Google Cloud and New Relic, what really sets the limit is what you allowed the key or account you created for the agent.
3. Read only, or read and act
The Google and Atlassian plugins are connected by choosing what the agent can do:- Read and act: it reads, and changes things when you say yes.
- Read only: it reads and can’t change anything, even if you ask it to.
Also
- What comes from outside is information, not orders. If an email, a document or a web page tells the agent to do something, it tells you instead of doing it.
- Only what’s needed. It brings just what you asked for; it doesn’t dump your whole inbox or all your chats on you.
- Not on the web either. When it browses, it doesn’t buy, pay, send or accept anything without your OK.
- Installing plugins: if the agent wants to add one, it asks you first.