The Archive · Android · Concepts

Powers and consent

The two gates every action passes — Android’s permissions and TALOS’s own powers — how an approval is scoped, and why what a conversation has seen matters.

Checked on Android 0.1.38

A newer version is out (Android 0.1.40): some details may differ.

Before TALOS does anything on your behalf, two gates must open. Android decides what the app may reach; TALOS decides, by your rules, what the agent may do with it.

Android permissions are asked only when a feature needs them, at the moment you use it, and Android always has the final word: anything granted can be taken back in the system settings. Settings → Privacy and permissions lists every access the app can have and its state — allowed, not requested, not allowed, blocked by Android — and, for the ones that need no permission at all, says so instead of leaving a blank. Each row says why TALOS would need it.

The full list, with how each permission is obtained, is on Android permissions. A permission Android granted is only the first gate: every tool still passes the second.

Every tool declares the power it uses:

Power In Settings What it covers
Read Read your things The Library, notes, tasks, memory, the calendar, the state of the phone.
Write Create or change things A note, a document, a switch, an alarm — on the phone or in your records.
Off-device Send anything off this device A search, a page, a message, a model download — or words spoken out loud.

Each power is set to Always allow, Ask me every time or Never allow, in Settings → Agent Tools. By default all three ask. When a tool asks, a card appears in the chat with what it is about to do; the card itself offers to always allow, so “ask me” costs one question per tool. See Choose what TALOS may do.

Below the powers, each tool has its own switch. A tool you switch off is not sent to the model and cannot run.

Choosing a tool and being allowed to run it are separate decisions. An approval covers the exact, validated input it was shown — not the tool in general, and not a different input the model tries next.

How long an approval lasts is your choice, under Approval duration:

  • This message — it ends with the answer;
  • The conversation, while trusted — it lasts for the conversation, and expires as soon as an untrusted page or document enters it.

Revoke saved authorizations removes every “always” you gave; the tools stay on and ask again.

TALOS keeps track of where content comes from — you, something derived from it, or the outside world — and whether a conversation has already read your private data or taken in untrusted outside content. Reading private data, reading something untrusted, and then sending something off the device is treated as more dangerous than any one of the three alone, and a tool that would send is judged with that history in view.

Memories and Library documents are context, not authority: what they say cannot change these rules. Doctor shows, for the current chat, whether private data was read and outside content entered.

Each tool also carries a risk level, from touching nothing of yours to acting in the world in a way that cannot be taken back, and whether its effect can be undone. Both are listed for every tool on Consent.

Three consents in Settings → Privacy and permissions, under Content and models, decide what reaches a model at all:

  • Library access — whether TALOS can search and read your Library files;
  • Writing memories — whether it can save memories for future conversations;
  • Sending attached images — whether an image you attach can be sent to the service that answers.

Turning on “hey TALOS” means talking to TALOS without touching the screen, so it cannot stop to show you a card. Before it turns on, TALOS asks once to set all three powers to always allow. Before anything that cannot be undone — deleting, sending, calling — it says so out loud and waits for your answer. See Call TALOS from anywhere.

Type to search the guides.