Keeping people in control as AI agents act.
Our vision keeps people in control as agents act, with chosen context, explicit permissions and private human decisions.
AI began, for many of us, with a question and an answer. We asked for explanations, help with writing or a way through a problem. It offered suggestions. We decided what to do with them.
Useful help soon reaches closer to our lives. A decision may depend on your commitments, conversations or preferences. Some of that information is private. Some belongs to other people. Asking for help should not mean handing over everything around the task.
Then comes action. An agent could arrange something for you instead of merely suggesting it. Software connections such as APIs can let it read a calendar or book a room. But the ability to make a booking does not establish your agreement to spend money. Knowing why someone cannot attend does not grant permission to share the reason.
The next step reaches beyond one person. Your agent could work with a friend's agent to find a weekend together, or help a team coordinate its work. Less chasing, less repeating yourself, more time for the things you meant to do. As that help grows, so does the importance of whose wishes it follows, what it shares and where it stops.
We are building Situation to keep people in control through that change. An agent can finish a task and still misunderstand the people involved. Our aim is help that respects people's intent, privacy and choices, with boundaries the software checks.
Let an agent help through a smaller view
Situation is being built around three connected views: a focused view for the agent, a private place for you to decide, and the real website on the trusted side. You choose the purpose, information and actions. The software carries those choices into the work.
The agent's view contains selected task information and defined actions. Your private view lets you review consequential details and approve the exact choice. The real website keeps its credentials and private context on the trusted side. If important details change, the software should ask again. A model's interpretation must not turn into permission.
Imagine asking an agent to prepare a cart. It could help compare permitted choices and bring the decision back to you. Preparing a cart, committing to an order and paying are different permissions. Useful help should respect the choices you make about each.
Our goal is to help with the requested task while disclosing less. The launch experience is being designed around that purpose, with human control over information and consequences.
Better questions before more agency
Getting useful help often means knowing how to write the right prompt. People have to understand what the system needs before they can explain what they need. That is fundamentally broken.
Designers and engineers spend decades learning how to discover requirements, and still miss things. A good designer understands the situation, asks useful questions and notices what nobody thought to mention. Software should carry more of that work.
Agents are already writing software. When a requirement is unanswered, a coding agent may choose how an app behaves, who gets access or what information it shares. The app can appear to work before people have settled those choices. People should be at the center of software. Agents should help uncover missing decisions, rather than quietly make them.
The same applies when an agent helps with a website. Which account is involved? What may it see? Is the request to prepare a cart or to pay? Which change should require a fresh decision? Situation's direction is to make those questions concrete, preserve people's answers and connect them to rules software can check. Models help us understand. People decide the intent, the permissions and the privacy.
The foundation for personal and social agents
APIs will continue connecting software underneath. Personal Programming Interfaces, or PPIs, are the future layer that carries people's chosen context and explicit rules into that work.
A permission for one task should not silently follow an agent into another. An organizer's permission to arrange a trip should not become everyone's permission to disclose private details to the organizer's model provider. As agents from different companies work together, those distinctions need to remain meaningful.
A PPI should make ten everyday expectations clear:
- Know who is involved and whose wishes the agent represents.
- Have a clear purpose for the help it gives.
- Define which actions are allowed and when to ask first.
- Use information only for the purpose and audience each person agrees to.
- Keep parts of our lives separate unless we choose to connect them.
- Define when permission starts and when it ends.
- Stay within the limits we set on money, time and other resources.
- Make it clear who agreed to what.
- Let us see the choices, actions and results.
- Let us change our minds and withdraw permission.
These are requirements for the future platform, not a promise that every agent or provider enforces them today.
Keep people in charge
Useful autonomy should come with a clear account of what happened, what was shared and how to withdraw permission. Ending authority cannot recall information someone has already received. Different features have different data flows; read the privacy information before supplying details about yourself or someone else.
The ghost browser experience explains the product we are building. Privacy boundaries describes information use and the limits that matter when making a choice. The existing shared-application host remains another foundation, with supported questions, previews and scoped commands.
The ambition is more room for living, creating and being together, with less work managing software around us. AI does the work. People set the limits. Let agents help without handing over everything.