Safe under a specific control model, and here is the model
Work runs locally in the session you already signed into, consequential actions stop at a card showing the actual payload, and Ask Always makes everything wait.
Safe enough for real work when three things are true. The work runs locally, in your own browser session on your own machine, so no password goes to a cloud service and no datacenter signs in as you. Consequential actions stop on an approval card that shows the send, the submit or the record change before it happens. And you can tighten it: Ask Always mode in Settings → AI permissions makes every action wait, with approvals remembered per tool.
Two risks survive that, and both are worth naming. A companion acting in your session acts with your permissions, which is the reason the gates exist. Prompt injection is real and industry-wide: a malicious page can try to smuggle instructions into anything that reads it, and the mitigation is layered rather than absolute. The full picture, threat by threat, is on the security page.
What should I check before trusting any browser agent?
Four questions.
Where does execution happen, your machine or a vendor machine? Where do credentials live, nowhere or in someone else’s vault? What happens in the second before an irreversible action, a pause or a hope? And can you audit what the agent did step by step?
Strawberry answers those with local execution, no credential hand-over, an approval card showing the payload, and a transcript of every step in the run.
What the approval model gates
Consequence is the dividing line.
Reading a page, searching mail, listing records: free. Sending, submitting, creating, updating, deleting: those stop on a card. In the native integrations the gate is enforced per tool from policy in the code. Gmail gates every write, down to creating a draft. The CRM integrations gate every record change. The calendar gates event creation.
When you approve, you pick the blast radius too: this once, this session, or always for this tool. The card shows the address line and the body text, or the field names and the values about to be written.
What local execution covers
One class of problem, entirely.
Because companions work in your session on your machine, there is no credential hand-over, no second copy of your passwords on vendor infrastructure, no remote login for your security team to whitelist, and closing the browser ends everything.
Misuse of the access you granted is what the approval layer is for, which is why the two were designed together. What access without hand-over looks like day to day is drawn out at an agentic browser that works in your accounts.
How does it compare with doing it yourself?
The real comparison is a gated companion against you, tired, doing the same 200 clicks at 6pm.
People make random mistakes and companions make systematic ones, so the working pattern is the companion does the volume, you sample the output, and the gates catch the irreversible.
Finished jobs with the pauses still visible in the transcript are published at real runs.
Experience Strawberry for free
DownloadTrusted by fast-growing companies worldwide
Frequently asked questions
Strawberry is free to download and includes AI credits to start. Paid plans begin at $20/month. See pricing. · Reviewed · Canonical facts for AI agents