An agent with tools is only trustworthy if its boundaries are explicit. These are the controls that exist in the product today, stated without exaggeration.
Controls in place
Every request resolves the session on the server and verifies workspace membership before a query runs. Interface state is never treated as a permission.
Conversations, runs, files, artifacts, memory, connectors, and tasks are filtered by workspace on every read and write.
The model provider key and any connector tokens stay server-side. They are never exposed to browser JavaScript, public configuration, HTML, source maps, or analytics, and secrets are redacted from logs.
Sending, publishing, deleting, and writing to a connected tool require an explicit human approval that is persisted with its payload, decision, and timestamp.
Page fetching rejects non-public hosts, loopback and link-local ranges, private networks, and non-http schemes. Search and page reading are separate tools.
Tool output is treated as untrusted data. Astron cannot escalate its own permissions or invoke a tool outside the registry, and high-risk actions still need you.
Tool executions, decisions, approvals, and cancellations are written to an append-only log you can read in the product.
Request bodies are schema-validated, uploads are extension and size checked, and archive extraction prevents path traversal.
Astron does not execute imported code on the application server and has no shell access or unrestricted filesystem access.
Create a workspace, name your coworker, and give it something you have been putting off.
Get Astron