MIAO AGENT · CAPABILITIES AND BOUNDARIES

Let the Agent handle work.
Let permissions set the boundary.

MIAO Agent is a controlled collaborator inside the server-side workspace: it reads resources allowed by the current app, proposes a plan, calls registered actions and waits for confirmation when needed. It is not a general-purpose agent that can run arbitrary code.

Demo data / illustrative Model names, records and receipts on this page are examples, not production capability or real customer data.

One inspectable run loop

Three practical work scenarios

Requests and approvals

Turn “request a monitor” into fields, an approval flow and a task.

  • Read the request table and member roles
  • Draft an approval plan
  • Confirm before writing or notifying

Sales and service records

Create a follow-up summary or next task from customer records.

  • See only fields visible to the user
  • Call registered status-update actions
  • Recheck permissions and record versions

Controlled data collection

Read credential-free HTTP(S) sources under declarative rules and prepare a draft.

  • Declare source, fields and frequency
  • Carry no browser token or private credential
  • Authorize publishing or bulk writes

What it can read and do

Can execute

Server-enumerated registered actions such as creating drafts, updating allowed fields, sending configured notifications or running declarative collection.

The harness/Jev selects legal actions; arbitrary tool names are not accepted.

Cannot execute

It cannot run shell commands, arbitrary user source, unauthorized HTTP or expand the creator’s business permissions.

Operations and security ↗

Confirmation, cancellation, budget and durable runs

A plan shows impact, action count and budget first. Writes, releases, notifications or wider visibility enter “awaiting confirmation”; users can reject or cancel, while expired plans and changed permissions block execution. Authorized background tasks may continue after the browser closes and keep an auditable receipt; they do not retain browser login tokens.

One run receipt demo / illustrative

Illustrative run: customer follow-up · 2026-10-08

Model (illustrative)
demo-model-not-production
Plan
Read 24 → create 3 reminders → await confirmation
Permission scope
workspace:sales · app:follow-up · field:next_action
Events
Describe ✓ Observe ✓ Decide ✓ Review → pending
Final receipt
No write executed: user cancelled confirmation
Budget
demo limit: 20 actions · consumed: 3

Records and model names are illustrative.

What remains available when the model is offline?

Still available: deterministic pages in published apps, sign-in and permission checks, authorized CRUD, historical receipts, queued-run status and declarative collection results that do not depend on a model.

Waits: Agent plans to create or change apps, plus model-dependent summaries and suggestions. After recovery, permissions and record versions are checked again.

Not promised: this is not an open-ended general agent; an online model still gets no shell, arbitrary source, arbitrary HTTP or privilege escalation.

Read next