GuidesBy featureAnyone trying an agent that keeps working while they are away
Giving a persistent agent one job without handing over the keys
For Anyone trying an agent that keeps working while they are away.
Agents that run on their own cloud computer stay signed in to your tools between sessions. That persistence is the point, and it means the thing you are really configuring is access, not prompts.
When to use this
You have access to an agent that keeps working after you close your laptop. It has a browser, a file system and a terminal of its own, and it can sign in to the tools you already use. You want to try it on something real without giving it the run of your accounts.
- Carries out a repetitive job across several signed-in tools without being watched
- Keeps working between sessions, so a routine can pick up where it left off
- Holds context across a job that is too long to sit through, then hands you the result
- Stops and asks before named categories of action when you have set those boundaries
Workflow
Pick one job you could check in ten minutes and undo if it went wrong, and start there rather than with the impressive job
Create a separate account for the agent with access to only the apps and folders that one job needs, and do not reuse your own login
Sign in on the agent's machine yourself for anything needing a password, a two-factor code or a CAPTCHA, and understand that the session stays there afterwards
Write down what it should do when something is missing, so it flags the gap rather than filling it with last period's figure
Set approval boundaries by category before the first run: sending messages or invitations, publishing, purchases and transfers, deleting or overwriting, changing permissions, production changes, and accepting terms
Run it once, read what it actually did rather than only the output, and compare that against what you expected
When the trial ends, sign the machine out of every service and delete the files it left behind
Prompts to try
Use it, adapt it, and make it your own.
Your job is [one specific recurring task]. Take the figures only from [named sources]. If a source has not refreshed or a number is missing, stop and tell me rather than estimating or reusing an older value. Before you send anything, publish anything, spend anything, change any permission or delete any file, stop and ask me first. When you finish, list every site you signed in to and every file you saved.
Human lens
- You choose the one job that is safe to hand over, and the account it runs under
- You type the passwords and the two-factor codes yourself, because those steps are human-only
- You decide which actions must stop for approval rather than accepting the defaults
- You sign the machine out and delete the files afterwards, because that part is not automatic
What to avoid
- Separate agents are usually not separate accounts. Where they share one computer, one agent's logins, files and stored credentials are reachable by the others, whatever you named them
- Deleting an agent tends to remove its profile, conversation and routines while leaving the signed-in sessions and downloaded files exactly where they were
- Automatic review of an agent's own actions is itself a model making a judgement, and providers say plainly that it complements least privilege rather than replacing it
- A broad allow rule written for convenience on day one is the rule that lets something through in week three, when the site it acts on has quietly changed
- Persistence cuts both ways: an agent that keeps working also keeps holding access while nobody is watching it
Tools that fit: Grok, Claude, ChatGPT, Gemini · Reviewed 2026-08-12