cartographer
latest
false
Cartographer user guide
- Overview
- Installation and setup
- Installation
- Local security configuration
- Permission setting best practices
- Choosing the LLM model
- Usage and limits
- Getting started
- Trust and compliance
- Governance
- Features
- Reference
- Troubleshooting
- Backup and restore
Permission setting best practices
Recommendations for configuring Cartographer permissions securely, by role — individual users, IT administrators, and developers creating skills.
For individual users
To configure Cartographer securely as an individual user, take the following steps:
- Start with Cautious mode until you understand what the agent does.
- Enable only the tool categories you need — if you don't use command execution, disable it.
- Review tool permissions after installing new skills — skills may request additional capabilities.
- Use Protected files and Blocked apps/sites for sensitive directories and destinations (tax documents, medical records, etc.).
- Turn on Guarded mode while inside a business process that touches confidential information.
- Pin important sessions so you can review what the agent did later.
For IT administrators
Deploying and enforcing these settings centrally, across all users, is covered in Governance with Automation Ops, including the recommended baseline for regulated environments.
For developers creating skills
To develop skills that follow good permission-setting practices, take the following steps:
- Request only the permissions you need — don't ask for UI automation if your skill only reads files.
- Document required permissions clearly in your skill description. See Sharing skills with your team.
- Handle permission denials gracefully — explain to users why a permission is needed.
- Test in all three Approval mode settings to ensure your skill behaves appropriately.
- Don't rely on being able to reach a site the user or organization has blocked — blocked websites are configured specifically to keep the agent out.