Personal & Consumer Use Cases Best Practices
Ten practices for scoping a personal agent's access, autonomy, and retention before it touches real mail, chat, calendar, or shell.
Busca en todas las páginas de la documentación
Ten practices for scoping a personal agent's access, autonomy, and retention before it touches real mail, chat, calendar, or shell.
Use this list when excitement about always-on assistants outruns threat modeling.
/pause kill switch that does not require redeploying the host.| Stage | Habits | Exit criterion |
|---|---|---|
| Intent | 1 | Single job with a success check |
| First deploy | 2-4, 7 | Read-only digest in an allowlisted channel |
| Real accounts | 5, 8 | Minimal scopes; retention written down |
| Power features | 6, 9 | Shell/purchases only with gates and caps |
| Ongoing | 10 | Wipe drill completed once |
.env live in random cloud folders.Treat 1, 2, 3, 5, and 7 as mandatory before production-like use. Treat 6 and 9 as mandatory before shell or purchases.
Use a throwaway account. Never demo auto-send on your primary identity.
No. You still choose permissions, payment methods, and what you paste into chats. Vendor UX is not a threat model.
On device loss, collaborator changes, suspected leak, and on a calendar cadence you will actually keep (for example quarterly).
You trust the digest enough to open fewer apps, with zero unintended outbound messages.
Prefer human-edited prefs. If the model may update them, log diffs and require approval for security-relevant keys.
They do not. Any always-on personal host with tools must pass the same access gates; treat project names as patterns.
Still apply 1, 7, 8, and 9. Skip mail scopes entirely if they are not required.
Yes. Maintain a tiny VIP break-glass rule if you need true emergencies, and log every break-glass fire.
Beside your secrets manager inventory and the host's README - not only in a chat history.
Over-scoped bot in a group chat or open DM, plus a write tool, plus injected or careless instructions.
Anytime a tool is unused for a month or involved in a near-miss. Shrinking action space is a feature.
Stack versions: Pins from the category manifest (verify at build): OpenRouter (~315+ models, July 2026 pricing/fees); LangGraph 1.0+; CrewAI 1.14+; Microsoft Agent Framework 1.0; Vercel AI SDK 6; Pydantic AI (latest); LlamaIndex (latest); OpenAI Agents SDK (latest + MCP); MCP (Linux Foundation governance); A2A (HTTP+SSE+JSON-RPC 2.0); Solana
@solana/web3.js+@solana/spl-token.
Revisado por Chris St. John·Última actualización: 16 jul 2026