Skip to content

Trust and Vault

Trust decides what Otto can do in your apps. Vault decides how Otto uses your saved logins and cards, and it never shows them to the model.

Otto can sign in to a website, read a report, prepare a reply and complete a checkout. The model plans that work. The Otto server, not the model, decides which app actions, sign-ins and payments can run, and you can read every rule it applies.

flowchart LR
  you([You]):::accent
  model[Otto plans<br/>the task]
  trust{{Trust}}:::accent
  vault{{Vault}}:::accent
  apps[Your apps]
  site[A website]

  you -- asks --> model
  model -- app action --> trust --> apps
  model -- sign in or pay --> vault --> site
  you -. approves .-> trust
  you -. approves .-> vault
  site -- result, secrets masked --> model
Trust Vault
Protects Actions in your connected apps Saved logins, verification codes and cards
Checks The exact action, recipients and payload The task, the saved account and the exact website
Asks you when An action reaches other people or deletes data Otto wants an account you haven't allowed for this task
The model sees The action and its result Account names and status, never the secret
You review it in The confirmation in chat and Settings → Trust & cost Vault → Activity

Authority comes from you

A web page, email or file can't give Otto permission. Only your messages and approvals can.

Secrets have their own path

The server enters saved values into the website. The model never receives them.

One use, one result

An approved action runs once. If the outcome is unclear, Otto says so. You check the result, or ask Otto to, before any new attempt.

You ask Otto to What happens
Read your calendar or inbox It runs.
Add an event to your own calendar It runs.
Email an address you wrote in your message It runs, because the recipient came from you.
Email an address it found on a web page A review checks it against your request. If it doesn't match, Otto asks.
Delete files in your Drive A review checks it matches your request. If it doesn't, Otto asks.
Sign in to a site with a saved login Vault checks the account and website, then fills in the password privately.
Pay at a checkout You approve that one payment with your card's security code, or a yes if Do it for me is on.
Do something while it reacts to a new email on its own It only reads and drafts. Anything else waits for you.
  • Vault → Saved lists your logins, cards and saved browser sessions. Edit them, remove them or turn Sign in without asking on or off.
  • Vault → Activity shows every use, question, held attempt, reveal and permission change for 90 days.
  • Settings → Trust & cost shows what Otto spent on models and what it did in your apps. You can set a monthly spending limit.
  • Settings → Memory shows what Otto remembers about you and where it learned it.

Vault → Activity: this week Otto submitted logins twice, with one question you answered and labels for what you allowed and what you entered.