Computer use

Let agents see and drive the desktop apps on your computer, with a confirmation before every sensitive action.

Computer Use lets an agent work in the apps on your computer, outside the browser. It can read a window, click, type and use keyboard shortcuts, the way you would.

Nothing to turn on

Computer Use is always available. Settings → Plugins → Computer Use shows Always on.

There is no switch because an agent in Full Access could already reach your desktop through the command line, without any safeguard. Going through Computer Use is what keeps some apps blocked, asks for your confirmation and logs every action.

Which apps an agent can use

Agents can use any app on your computer, except these, which are always blocked:

  • Vato IDE itself,
  • ChatGPT and Codex,
  • terminals, such as Command Prompt, PowerShell, Windows Terminal, Terminal, iTerm2, Warp, Ghostty, Alacritty, kitty, GNOME Terminal, Konsole and xterm,
  • Keychain Access on macOS.

What an agent can do

  • List the apps that are running and open an app.
  • Read a window: its controls and a screenshot.
  • Click, drag, scroll, type text and press keys.
  • Restore a minimized window and bring it to the front.

Most actions are sent to the app in the background. The agent has its own cursor, so your mouse stays where it is. Some apps only react to real input: Vato then brings the app to the front for that action.

Approve actions

Looking at the screen and scrolling don't need your approval. Opening an app, clicking, dragging, typing, pressing keys and bringing a window to the front do, even in Full Access mode. A card appears in the conversation:

ButtonEffect
Approve onceAllows this action only.
Allow everything in this conversationAllows all Computer Use in this conversation, including later turns.
DenyRefuses this action.
Cancel turnStops the agent's turn.

Allowing everything in one conversation never applies to your other conversations.

Watch and stop the agent

While an agent acts, a pill at the top of the screen says Vato IDE is using your computer, with the app's name and a Stop button. A thin glow also outlines the screen. The agent can't see either of them in its screenshots. The pill and glow appear on Windows and macOS.

To stop the agent:

  • click Stop in the pill. The agent can't use Computer Use again for the rest of its turn.
  • or stop the turn from the conversation.

Check the activity log

Go to Settings → Plugins → Computer Use → Activity log. It lists each request with its result: Requested, Approved, Denied, Succeeded or Failed. Text the agent typed is never recorded.

Clear the log deletes this local history. Blocked apps and confirmations don't change.

Computer Use for Bots

Bots have their own switch, Shared computer control, in the Bot's Integrations and tools panel on Vato Desktop. Approvals still apply.

  • You can't turn it on from the mobile app.
  • Imported Bots start with Computer Use off.
  • Bots running on Vato Cloud can't use Computer Use: there is no screen there.

Known limits

  • In a minimized window, only actions on identified controls work. The agent can ask to restore the window.
  • Apps drawn on a canvas, such as some games or 3D views, expose no controls. The agent then has to click by position on the screenshot.
  • On Windows, some Store apps share one host window. If Vato can't tell which one to act on, it refuses rather than guess.