Muse Daily: Oct 2 — The 5-Step Safe Setup for an AI Assistant on Your Computer

The smartest AI assistant setup guide I've read this week is two slides long. Jacques Potts, a creator who goes by @jacqbots, posted it on Instagram on October 1 as part of his "AI Sauce" series: five steps for getting an AI assistant running on your computer without handing it more access than it deserves. His summary line is worth memorizing: earn the trust slow, widen access later.

The guide is written for tools like Meta Muse for Mac and ChatGPT's desktop assistant, but the steps apply to any agent that can read your files, touch your apps, and take actions on your behalf. I read the whole carousel end to end. Here's the method, expanded with the practical details the slides gloss over.

Photo: Niklas Veenhuis niklasveenhuis (CC0)

Why this matters more than it sounds

An AI assistant on your computer is not a chatbot. Once you connect it, it can read your inbox, open your calendar, browse on your behalf, and in some configurations send messages or place orders. That's the entire point, and it's exactly why the setup deserves ten minutes of thought.

This week alone, the trade-offs made headlines. A journalist claimed Meta's Muse accessed his messages without proper permission; Meta countered that its permission model makes that technically impossible and that the AI had hallucinated its own explanation of what happened. A YouTuber separately said Muse gave out his home address and approved a Marketplace pickup he never confirmed. I covered both stories yesterday. They both come down to the same question: does the agent respect the boundaries you set?

Potts's checklist is the closest thing I've seen to a sensible answer. It doesn't require any technical background. Here's how each step works in practice.

Step 1: Install it, keep most permissions read-only

When the installer or the first-run flow asks for access to your email, files, messages, or calendar, the default in your head should be "no." Pick read-only wherever the app offers it. Read-only means the assistant can look but can't send, delete, buy, or change anything.

This matters because setup is the one moment you're guaranteed to approve everything carelessly. You're excited, you're clicking through, and every prompt looks like a blocker. It isn't. Almost every AI assistant works fine with limited access while you learn what it does with it. Start narrow; you can always widen later. You can't un-send an email.

Step 2: Connect only the apps you actually use

The temptation is to connect everything the assistant offers "just in case." Don't. An agent connected to an app you never open is all risk and no value. It's a door into your life that nobody walks through except the agent.

Pick the two or three apps where an assistant would genuinely save you time: maybe your email and calendar, maybe your browser and a shopping app. Leave the rest disconnected. If you find yourself wishing the assistant could see something, connecting it later takes about thirty seconds. The reverse: cleaning up after an agent misused access you forgot you granted — takes much longer.

Photo: Yuri Samoilov (CC BY 3.0)

Step 3: Start every connector on the lowest access

This is the step most people skip, and Potts is right to give it its own slot. Connecting an app is not a single yes-or-no decision. Gmail-style connectors typically offer tiers: no access, read-only, and read-plus-send. Calendar connectors can read events, or they can also create, edit, and delete them.

Choose the lowest tier that could work, then run it for a while. For email, that's read-only. Enough for the assistant to summarize your inbox, not enough to reply. For your browser, that's "watch and report" rather than "click and buy." The permission screen is the cheapest safety control you have, because it's the only one the agent can't talk its way around.

Step 4: Hand it one real chore first

Potts suggests a daily price check as the first assignment: one routine, clearly defined, with a visible result. That's a better test than any vague "play around with it." Here's why: a single concrete task shows you the assistant's failure modes in a contained area. Does it ask before acting? Does it report what it did accurately? Does it handle edge cases, or does it confidently wing it?

Good first chores share three traits: they repeat (so you can compare outcomes), they're verifiable (you can check whether the price it reported is real), and they're harmless if they go wrong (a wrong price is annoying; a wrong email is a problem). Inbox triage, a daily news digest, or tracking one package all qualify. Pick one. Watch how it behaves for a week or two before adding more.

Step 5: No sending or buying for two weeks

This is Potts's own "sauce," and it's the step that elevates the list from decent advice to an actual method. For the first two weeks, the assistant is not allowed to send anything, buy anything, or publish anything. Read, summarize, draft, propose: yes. Execute: no.

Two weeks is long enough to learn the assistant's habits: does it ask permission the way you expect, does it describe its actions honestly, does it respect the boundary rules you set in plain language? Nobody gets the keys to the house on the first date.

Photo: सुबोध कुलकर्णी (CC BY-SA 4.0)

My take: step 5 is the one I'd fight for

Steps one through four are good hygiene. It's the kind of thing security people have said about every new technology since the fax machine. Step five is different. It builds in a feedback loop: you get to observe the agent's judgment before its judgment has consequences.

The failure mode this guards against isn't a malicious AI. It's a confident one. An assistant that drafts a perfect email and then, on its own initiative, sends it to the wrong person is not evil; it's an agent with a permission model you never actually tested. Two weeks of read-only plus one watched chore is how you test it.

One more practical note. Don't ask the assistant what it can access. Ask the settings screens instead. If this week's iMessage dispute taught us anything, it's that an AI can give a polished, confident, completely wrong account of its own behavior. System Settings on your Mac, and the connector list inside the assistant's app, are the source of truth. Check them yourself; it takes five minutes.

Worth it if: you're about to install a desktop AI assistant and want a setup that won't embarrass you. Skip this if: you've already been running one for months with approval gates on: you've effectively done steps one through five by accident.

The two-week rule won't make an assistant perfect. It will make it legible. And legible is what you need before you let anything with your data act on its own.


Sources:

- @jacqbots (Jacques Potts), "HOW TO SET UP AN AI ASSISTANT ON YOUR COMPUTER SAFELY," Instagram, Oct 1, 2026: https://www.instagram.com/p/Dd9UOW3l2ll/

Want to try Muse yourself? muse.ai — use my invite code P74B9O at signup. This is my referral code, so I'll receive tokens too.

댓글

이 블로그의 인기 게시물

Muse Daily: Oct 1 — Meta's "Muse for Small Business": An Agent That Works Your Back Office

Muse Is Invite-Only Right Now — Here's Exactly How to Get In

Muse Daily: Oct 1 — The Phone Calls Weren't Always AI: What the "Human Concierge" Story Means for You