- Overview
- Installation and setup
- Getting started
- Trust and compliance
- Security overview
- Data security and compliance
- Governance
- Features
- Reference
- Troubleshooting
- Backup and restore
Security overview
Authorization and restriction controls in Cartographer, including security modes, for teams evaluating it before deployment.
UiPath Cartographer is an AI assistant that runs on your work computer. You ask it to do things in plain language, such as "document this process" or "draft the future-state design," and it carries the task out across the applications and systems you already use.
To be useful, Cartographer acts on your behalf. Evaluating its security comes down to two questions: how do you stay in control of what it does, and how does it reach your system? This page answers the first question and summarizes the second. See Data security and compliance for the full data-handling and network detail behind these claims.
In short
- To do its work, Cartographer sends the content a task needs, including screenshots, to a large language model. Every request passes through the UiPath AI Trust Layer: the connection is encrypted and authenticated service-to-service, and a contractual ban prohibits training with your data. You can also bring your own model, including one hosted locally, in which case the entire data flow stays under your control.
- You control them in two complementary ways: authorization (it asks before acting) and restriction (hard limits it cannot cross). Both do.
- Every control described on this page and in Governance with Automation Ops can be enforced and locked centrally through UiPath Automation Ops.
- As an individual user, you configure your own approval mode, screen context, execution mode, and the rest of your local security settings — see Local security configuration.
Two kinds of control
| Control | What it means | Where it is configured |
|---|---|---|
| Authorization | What approval mode governs. It asks before acting, and can be set per operation (Allow, Ask, Block). Keeps a person in control of when it acts. | Local security configuration, or centrally through Governance with Automation Ops |
| Restriction | Independent of any approval: the operating-system sandbox, blocked paths, blocked apps and sites, disabled tools, credential protection, and automatic redaction. Guarantees that certain things never happen at all. | Local security configuration, or centrally through Governance with Automation Ops |
Authorization keeps a person in control of when it acts. Restriction guarantees that certain things never happen at all. Using both together is what makes a regulated deployment safe.
Approval mode
The most important authorization control is approval mode. It sets how much Cartographer does on its own versus how often it asks you first, and applies to all chats.
| Mode | Runs automatically | Asks your approval for |
|---|---|---|
| Cautious | Nothing | Every operation |
| Adaptive (recommended) | Read-only actions (read a file, view the screen, list emails) | Any write, change, or execute action, plus any action it judges to be irreversible or high impact (for example, submitting a loan application or making a payment) |
| Full access | Everything | Nothing (not recommended outside trusted, thoroughly tested environments) |
In Adaptive mode, reading is free but any change is gated, and Cartographer asks you whenever an action looks irreversible. Entering a password is always an explicit, one-time approval, in every mode.
Approval mode sets the default for the granular, per-tool, per-file, and per-app/site controls in Security settings reference — you can override individual entries there regardless of which mode you have selected. See Approval mode in Local security configuration for the full breakdown.
Settings storage model
Cartographer separates user-configurable settings from protected permissions into two files: a plain-JSON settings file you can edit directly, and an encrypted file holding tool permissions, Approval Mode, and authentication tokens that's only modifiable through the Settings UI. This design prevents a compromised agent or malicious skill from escalating its own permissions — even if an agent could modify the plain-JSON file, it cannot access or change the encrypted one. See Settings file locations for exact paths and what each file contains.
You can also tune how often Cartographer asks before acting on applications and sites, and block specific destinations or entire sensitive categories outright — see UI automation in Security settings reference.
Scripting and code execution
When a task needs it, Cartographer can run commands. A command can do anything the signed-in user can do, so this pathway has the strongest controls.
- Sandboxed by default: Code execution runs inside a kernel-enforced container (Windows AppContainer), which confines the filesystem, network, and process access, and walls off credentials such as SSH keys, cloud credentials, and keychains.
- Your choice, by mode: The strictness of the sandbox follows approval mode, and it can be turned off entirely in Full access mode — not recommended outside trusted, thoroughly tested environments.
See Terminal and files in Security settings reference for the full configuration options.