Permissions & access
You decide what your assistant can access and when it can act on your behalf.
Perisclaw only ever does what you allow. You decide which services it connects to, which chats it can see, and what it can do in each. You can change any of it at any time from the Permissions page in your dashboard.
What your agent can access
Your agent only reaches what you connect and authorize. Depending on your setup, that can include:
- WhatsApp: your chats, contacts, groups, media, and message history.
- Calendar: events, attendees, and availability on Google Calendar or Outlook.
- Email: your Outlook mailbox once you connect Microsoft 365.
- Files: documents in Google Drive and Sheets, or OneDrive.
- Contacts: your Google address book, if you connect it.
- Other tools: anything you explicitly connect through a connector.
It uses this only to carry out what you ask: drafting a reply, scheduling a meeting, tracking a follow-up. See Connect your apps to manage what is linked.
What it can read
Your agent can see your chats in order to do its work. That is what makes it useful. Any chat you block is the exception: it cannot read, search, summarize, or quote a blocked chat at all, and blocking holds in every mode. Say “never read <chat>” in your self-chat to block one.
When it can act
Nothing goes out on its own unless you have allowed it. One overall setting decides how forward your agent may be outside your self-chat:
- Strict: it acts only when you summon it with
/claw. - Default: it may also keep participating in chats you explicitly hand over, for the purpose and period you specify. This is the recommended setting.
- Auto: it can also respond to new incoming messages in one-to-one chats, following the plain-language rules you save. Groups and blocked chats are excluded.
Auto has one Engagement rules box. Describe which one-to-one conversations it may handle, what it should do, and when it should wait, stay out, or bring the request to you. A broad rule such as “handle every eligible 1:1” lets it answer a simple “Hi” naturally; a narrower rule such as “engage when someone wants to schedule time” waits until the person’s purpose is clear. Money, binding commitments, sensitive requests, and anything outside your rules come back to you.
A rule like when this happens, do that belongs in an Automation, not in a global permission rule. A goal that may span chats belongs in a Mission. Neither silently turns on participation in every message of a chat. You don't have to pick; ask for what you want and Perisclaw sets up the right one.
How a message reaches another chat
- You ask it to. It drafts the message, shows it in your self-chat, and sends only once you approve.
- You invoke it with
/claw. It responds directly in the chat where you called it. You are standing in that chat, so there is nothing to preview. - You hand it that chat. Tell it to handle a thread and it acts there on its own, for the purpose you gave it, until that grant expires or you stop it.
To learn how handed-over chats and per-chat exceptions work, see Chat modes & autonomy.
It confirms before it acts
By default, anything it sends or changes on your behalf is shown to you for approval first. When you want it to run longer work without checking in at every step, you grant that autonomy deliberately. Even then it never commits money, agrees to a price, or makes a binding promise without checking with you.
Actions that always stop for youHard limits that no setting removes
A few actions are capped no matter what you have allowed, because they cannot be taken back:
Sending the same message to many chats. It stops well before anything looks like a broadcast, reports exactly who has and has not been messaged, and warns that bulk outreach can get your number flagged by Meta. Splitting a broadcast across turns does not work, by design.
Deleting chats or messages in bulk. Hard limits per turn, with a precise report before asking to continue.
Adding people to groups en masse. Rejected outright. It offers the group invite link instead, which people join by choice.
Anything running unattended (an Automation or a Mission) gets no confirmation path at these limits. It stops and brings the decision to you.
What it won't say in someone else's chatYour private context stays private
When your agent acts inside another person’s chat, it treats them as an outsider. It will not disclose your other conversations, calendar, email, files, or notes to them, even if they ask directly. If someone probes for your private information, it declines and tells you about it instead.
Manage your data and connections
Connect a service when you want the capability and disconnect it the moment you do not; disconnecting immediately stops all future access. You can also delete specific data, clear what your agent remembers, or delete your account entirely. See Account & settings.
For how your data is stored and protected, see Privacy & security.