Every action Alden takes routes through its Governance Engine first. Here's how the three permission categories work.
Site sign-ins follow per-site rules you set. A given site can always be trusted to sign in automatically, always require your confirmation, or never be signed into automatically at all.
Ordinary clicking, typing, and navigating that you asked for doesn't interrupt you. Genuinely consequential sub-actions, a file upload or download, checkout, a purchase, are what trigger an approval prompt, governed by this category.
Anything that reaches outside the conversation itself, sending an email or message, creating or editing a file, follows the same rule, set per action type, your call.
Always lets Alden carry out that category of action without stopping to ask, every time it comes up. Ask Every Time means Alden will pause and wait for your explicit confirmation before it proceeds, no matter how many times the same action has come up before. Never blocks the action outright, Alden won't attempt it, and will tell you it's not permitted rather than silently skipping it.
Authentication, Browser Automation, and System Actions cover meaningfully different kinds of risk. Signing in somewhere is different from clicking through a multi-step checkout flow, which is different again from sending an email on your behalf. Splitting governance into these categories means your comfort level with one doesn't have to apply to the others, you might be happy letting Alden sign in to trusted sites automatically while still wanting to approve every file it sends.
Regardless of your permission settings, a payment completes only on your explicit spoken confirmation, and Alden pauses and hands control back to you for CAPTCHAs and legal agreements rather than attempting to solve or bypass them. Both are hard boundaries in the product, not configurable settings.
Separately from these three categories, Alden keeps a trusted Alden Workspace folder on your machine: files you deliberately place there become working content Alden can read and edit as part of a task. Everything else on your machine stays off-limits unless you explicitly grant Alden access to it.
Governance preferences aren't fixed at onboarding, you can revisit and change any category at any time as you get a feel for how Alden behaves. Many people start conservative, with most categories set to "Ask Every Time," and loosen specific low-risk categories once they've seen Alden handle a few tasks the way they expected.