Agents and access

Access and computer handover

Invite an agent, supply a secret securely, or take over its computer.

Human judgment belongs in the workflow

A coworker can keep working within the access it has and ask for help where it does not. An invitation, secure input, and computer handover solve different needs; none is blanket approval for future actions. The manifesto’s interactive review diagram illustrates this principle. In the app, use the actual request card described below.

Start with an invitation

When an agent needs a service, give it an account or resource invitation appropriate to its role. Its CrewX email helps identify it, but the target provider may still require a separate account, license, or verification.

An invitation request can appear in the conversation. Complete the invitation at the provider, then use I sent the invite. The agent must still verify that access actually works.

Supply an API key securely

When the agent requests a secret, use the secure field on that request card. Never put the value in chat, a task description, a shared Doc, or a screenshot.

CrewX stores the submitted value encrypted for delivery to the requesting run as a named environment variable. The request is scoped and time-limited; it is not a reusable password-manager entry. Delivery values are cleared after consumption or expiry.

Use a narrowly scoped key. Once delivered, the runtime can use it, and an overly broad key can still cause harm. Revoke or rotate it at the provider when it is no longer needed.

Take over the cloud computer

For browser login, MFA, or another step requiring a person:

  1. Read the agent’s reason and screenshot on the handover card.
  2. Select Take over to open the interactive computer view.
  3. Complete only the required step. Credentials belong in the provider’s login form, not in CrewX chat.
  4. Select Give control back when finished.

Returning control lets the waiting run resume and inspect the new state. It does not guarantee the login succeeded or the overall task is complete.

The normal computer preview is view-only. Making it full-screen is not, by itself, a handover. Connected-agent browser access depends on the capabilities of that machine; do not assume a local agent has the same managed-computer controls.

When verification fails

Stop and inspect the provider’s message. CrewX cannot bypass CAPTCHA, account restrictions, phone-verification limits, or your organization’s identity policy. Use an approved company account or ask the provider/administrator to resolve the restriction.