Fail closed
No session, no tools
Every extension surface hides its application DOM until a live server check verifies the stored session is still valid. Invalid, signed-out, and unreachable states stay at the authentication gate.
Trust is visible
Chelai’s extension starts locked, requests page authority from a user gesture, and keeps every browser credential tied to one revocable device.
| Surface | What it can do | Control |
|---|---|---|
| Authentication | Call your configured Chelai server as the paired user. | Short-lived, single-use pairing followed by a labeled revocable token. |
| Site access | Mount the optional overlay and read the active page through bounded browser actions. | Requested for the click-time HTTP(S) origin; removable from the same control. |
| Page summary | Return URL, title, description, and bounded visible text. | Never returns raw page HTML. |
| Browser tools | Poll for authorized browser commands and report observable results. | Explicit connect/disconnect plus Chelai RBAC and human approval. |
| Floating chat | Render the shared composer over a trusted page. | Default-off preference; isolated extension iframe inside a shadow host. |
Fail closed
Every extension surface hides its application DOM until a live server check verifies the stored session is still valid. Invalid, signed-out, and unreachable states stay at the authentication gate.
Credential posture
Token plaintext stays on-device and is sent only to your configured Chelai server. The server never stores it in a readable form.
Agent output
Agent-rendered UI draws from a fixed, pre-approved catalog. Any HTML the agent produces is sanitized and mounted in an isolated sandbox with no network access of its own.
Production data
Production secrets live behind a dedicated, encrypted vault, separate from application data. No plaintext secret belongs in a storage row, trace, or response.
Inspect before install
The guided tour demonstrates the same explicit tool and approval states without acquiring any authority.