Let an assistant use your signed-in browser for a purpose you approve on your phone. AgentGate shares a checked task view and asks again before consequential actions.
Hi, just a reminder that Friday pickup is at 3:00 PM. Please let me know if that still works.
Original source text · checked for this task
Available controlsCompose replyReview draft
Approved on your phoneFind Ali’s daycare message and draft a replymail.example.com · 10 minutes
Purpose firstOne task, named before access starts
Bounded viewNo raw page or browser credentials
Phone approvalExact consequential actions return to you
Walk through one browser task.
Try the approval flow with fictional mail. Nothing here connects to your accounts or sends a message.
INTERACTIVE · SYNTHETIC DATA
01
Scope the taskPurpose, website and duration arrive on your phone.
02
Share a bounded viewThe assistant gets relevant text and usable controls.
03
Approve the exact actionSending waits for a second phone decision.
PHONE APPROVAL · 01 / 03
9:41●●●
Approve this browser task?
Purpose
Find Ali’s daycare email and draft a reply
Website
mail.example.com
Access
Read · fill · click · navigate
Duration
10 minutes
The request is fixed before you sign.
Your phone shows the purpose, exact website, permissions and time limit. An expired or changed request needs a new approval.
ASSISTANT VIEWScoped to Ali’s daycare
Ali’s daycare · Friday pickup change
Friday pickup is at 3:00 PM. Please let me know if that still works.
Source: mail.example.com · selected original text
Controls availableCompose replyReview draft
Bank notice and personal mail remain outside this view.
A smaller view, built for this task.
The synthetic assistant can use Ali’s message and reply controls. It receives no inbox dump, screenshot or cookies.
9:41●●●
Send this reply?
To
ali@example.test
Subject
Re: Friday pickup change
Message
Thanks for the reminder. 3:00 PM works for us this Friday.
The final action is a separate decision.
The draft and recipient appear on your phone. The assistant cannot approve its own send request.
Demo complete
The fictional reply was sent in this walkthrough. No real message left this page.
Waiting for your demo approval.
The assistant works. Your local AI checks.
In on-device mode, a separate model in your browser checks the remote assistant’s view and proposed actions against your approved purpose. Your phone signs the scope and consequential actions.
The assistant requests a task, allowed website, permissions and duration. Your phone signs that exact scope.
02
Use a checked view
The extension examines task tabs locally. Relevant source text and controls become a bounded assistant view; uncertain content waits for review.
03
Keep the last word
Consequential or uncertain actions return to your phone with the target and staged values before execution.
The assistant sees the work. You see the boundary.
AgentGate gives the assistant a task view through MCP. Website login and MFA stay with you, in your own browser.
Outside the assistant interface
Raw page structure and screenshots
Browser cookies and saved credentials
Unapproved tabs and unrelated content
Arbitrary browser scripts
Inside the approved task
Purpose, exact origins and time limit
Checked text and usable control references
Phone approval for consequential actions
Revocation and expiry that end access
Automatic local mode uses Chrome’s on-device model when available. If you configure remote inference, that provider receives locally redacted candidates, which may include unrelated ordinary content. Redaction can miss sensitive details. The acting assistant still receives only the selected view. Read the data flow.
Give the task a boundary.
Explore the synthetic flow, then connect your own browser when you are ready.