Talo Guide

Privacy and security

What data stays on your Mac, what can reach the AI provider, and what actions require your review

Before working with client data, check which project is open, which folders it has linked, and which agent you'll use. Talo saves work on the Mac, but a conversation with Claude Code or Codex can send the message, attachments, and project context to the provider. The agent can also read files available through its tools and permissions. Review the content before sending it.

Editing a document, diagram, or whiteboard in Talo doesn't contact an assistant on its own. In contrast, when you use "Review with Talo", the marked capture and comments are attached to the message you send to the agent.

Projects and memory

Talo separates instructions, memory, and conversations by project. Beta testing with synthetic projects observed no responses with another client's data. That observation is not the same as an absolute operating system barrier. Claude Code and Codex are command-line agents with their own permissions and settings. The CLI integration is still being validated. Before handling sensitive information, review their actual permissions and avoid linking unnecessary folders.

A project-less chat can use memory across projects when you turn that on. Citations show the project and source. Check them before reusing an answer. TALO.md holds instructions you write, while the Memory panel gathers indexed facts and data proposed from conversations.

Actions that need your decision

  • Installing or removing a skill, adding or changing an MCP connector, and installing or uninstalling an agent are actions reserved for you from Settings.
  • An automation can start on schedule, file change, or webhook without asking permission each time. It works on a copy of the project. Changes stay pending until you review and apply them. A new automation starts paused.
  • Publishing a deliverable to a cloud folder requires a separate native confirmation. The beta tested this flow with simulated folders. Testing remains with real accounts and sync.
  • Agent actions in the integrated browser go through permission checks. Especially review those that might send data, sign in, or download content.

An authorized conversation can create or modify files in its workspace without a prompt for each edit. The above controls don't replace reviewing the result. The agent can't approve automation changes on its own or take installation actions reserved for you.

Autonomous Mode and "Ask before acting"

New conversations with Claude Code or Codex start in Autonomous Mode: the agent reads, searches, and edits files within the project folder and runs commands in it without showing a permission card for each step. It's not a "do anything" mode. Talo starts the agent sandboxed in the project.

  • Inside the project, reading, creating, and editing files (for example in Work/) and running typical commands don't ask for approval.
  • Outside the project, Talo rejects writing to other folders or running commands outside the agent's protected environment on its own, no card, and the chat shows "In Autonomous Mode, Talo won't let the agent write outside the project folder…" Reading a file from outside is allowed.
  • Cloud folders: the agent can read them but never write to them. The attempt is rejected without a card with "Talo won't let agents write to cloud folders: save to Work/ and use Publish".
  • Still need your decision, even in Autonomous Mode: publishing to the cloud, adding or changing MCP tools or their sign-ins, installing agents or skills, confirming memories, writing to Jira, Linear or Trello, consulting a specialist, and activating an automation (which also starts paused and leaves its changes pending review). Tools from an MCP server you added also ask before use.

If you prefer to approve each edit and command, choose "Ask before acting" in the "Mode" selector on the compose bar (applies to that conversation from the next message) or as default in Settings › Agents and models › "Mode for new conversations". Existing conversations keep their mode until you change it. External channel conversations (Telegram and similar), team, and automation conversations don't use Autonomous Mode. They keep their own rules.

Credentials, logs, and comments

Claude Code and Codex use their own sessions signed in on this Mac. Talo doesn't need you to paste those credentials in a chat. Connector keys and tokens are managed separately. When you remove a connector, Talo deletes its saved key. Installer logs hide known credential patterns, but it's good to review them before sharing. Because of how they're stored internally, deleting data doesn't guarantee forensic erasure of every trace on disk.

To send feedback or diagnostics, Talo shows the content and asks for consent. You can exclude optional attachments. Review any captures or logs for client data or personal paths before sending.