Browser permissions — Pazi Documentation
Browser permissions
Browser controls determine whether agents may search, fetch pages, and perform supported browser actions. Use them to balance uninterrupted execution with deliberate review of site access.
Turn web browsing on or off
Open the selected agent's Integrations page and use the Web Browsing switch. The account starts with browsing enabled.
When browsing is disabled, supported search, fetch, and browser-use work returns a permission request instead of running. The agent cannot use a normal prompt to bypass the setting.
Choose a permission level
Under account Permissions, choose how supported browser actions should be handled.
Use saved access rules — recommended. Pazi can browse when browsing is enabled and remembers approved site/action rules from supported prompts.
Use fewer prompts — allows supported browser work to continue without requiring a saved page or site rule first. Use this with caution.
Changing the level can expand or limit what an agent does without asking again. Review the confirmation before applying it.
Review a permission request
Check the domain, action, and reason before approving. A page-navigation request is different from a form submission, purchase, message send, account change, or deletion.
Approval can interrupt a run that is blocked waiting for browser access and start the approved continuation immediately. Denying leaves the protected action undone; give the agent an alternative if the task should continue without that site.
Saved domain rules
Approved rules can remember supported decisions for a domain or action category. Open account Permissions to see active access, including the domain pattern and whether the rule allows a specific action category or all supported actions.
Delete a rule when the project ends, the site's ownership changes, an agent no longer needs access, or you want the next use to require review again.
Website login
When authentication is required, open Live View and enter the login directly on the verified website. Pazi does not need your password in chat.
Check the URL and certificate, use multi-factor authentication when available, and sign out or revoke the session when the agent should no longer access the account.
High-risk actions
Even with browsing enabled, you remain responsible for consequential actions. Use a two-step plan-and-approve workflow for purchases, production changes, outbound messages, account creation, financial actions, and deletion.
Prompt
Research the available options and prepare the form, but stop before submission. Show me the exact domain, recipient, fields, price, and irreversible effects so I can approve or change them.
Reduce prompt-injection risk
Web content can contain instructions intended to manipulate an AI agent. Use a separate web-research agent without sensitive integrations when researching unknown sites, then pass reviewed findings to a more privileged internal agent.
Keep saved rules narrow, avoid "allow all" for unfamiliar domains, and inspect unexpected requests that ask the agent to reveal data or change its instructions.