Computer-Use and Browser Agents: AI That Operates SoftwareSandboxing, permissions and security · Lesson 11 of 16

Credentials, payments and human approval gates

Article · 7 min · 8 min lecture

Video lecture

Credentials, payments and human approval gates

15 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 15

Credentials, payments and approvals

  • The golden rule
  • Safe login patterns
  • Agents and money
  • Approval gates that work

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

The golden rule

The model should never see a secret it does not need, and should never be the final authority on an irreversible action. Credentials, one-time codes, card numbers and bank details are exactly what injection attacks try to steal. Payments, sends and deletions are exactly what they try to trigger.

Handling credentials safely

Options, from best to acceptable:

  1. Use an API or delegated access instead of a login. OAuth-style delegated, scoped tokens are revocable and auditable; a password in an agent's context is neither.
  2. Human-in-the-loop login. The harness pauses at the login screen, a human authenticates (including MFA) via a remote view of the sandbox, and the agent continues in the authenticated session. The model never sees the password.
  3. Harness-injected credentials. If automation must log in, the harness (not the model) fills the login fields from a secrets manager using deterministic code, after verifying the domain matches exactly. Screenshots taken during this step are redacted or skipped.
  4. Session reuse with care. Pre-authenticated storage state (cookies) for a dedicated low-privilege account, scoped to one domain, rotated frequently, stored encrypted.

Never put passwords in prompts, task descriptions, spreadsheets the agent reads, or logs. Never let the model type a password it read from a page or document.

# harness_login.py: the model never sees the secret
import os
from urllib.parse import urlparse

def harness_login(page, expected_host: str):
    host = urlparse(page.url).hostname
    if host != expected_host:
        raise PermissionError(f"Refusing to enter credentials on {host}")
    page.get_by_label("Email").fill(os.environ["PORTAL_USER"])
    page.get_by_label("Password").fill(os.environ["PORTAL_PASSWORD"])
    page.get_by_role("button", name="Sign in").click()
    # MFA: pause for a human rather than automating the second factor
    page.wait_for_url(f"https://{expected_host}/dashboard*", timeout=180000)

Note the exact-host check: phishing pages that look like the real login are a classic way to harvest credentials from careless automation.

Payments and money movement

Agentic commerce is arriving (next module), but for your own agents the safe default is: agents prepare, humans pay. The agent can research options, fill a cart, draft a purchase order or pre-fill a transfer, then stop at an approval gate showing exactly what will happen. If you do allow agent payments:

  • Use virtual or single-use cards with per-transaction and monthly limits, restricted merchants and instant freeze.
  • Keep amount thresholds: below a small limit, auto-approve with logging; above it, require a human.
  • Use payment protocols designed for agents where available, which carry verifiable user authorization (mandates) rather than raw card numbers.
  • Reconcile every agent transaction against the approved request.

Designing approval gates

An approval gate is a harness state where execution pauses and a human decides. Good gates are:

  • Specific: "Submit this form to supplier-portal.example.ae with these 6 field values" rather than "Continue?"
  • Evidence-backed: show the screenshot, the target domain, the data to be sent, and the agent's reasoning.
  • Enforced in code: the harness cannot proceed without a signed-off approval record.
  • Risk-tiered: not every click needs approval, or people stop reading (approval fatigue).
TierExamplesGate
0: ReadNavigate allowlisted pages, read, screenshotNone; log only
1: Reversible writeSave a draft, add to cart, fill a form without submittingBatch review or sampling
2: External effectSubmit a form, send a message, publish, change a settingPer-action approval
3: Money or irreversiblePay, delete, transfer, accept legal termsPer-action approval by an authorized person, plus limits

Hands-on: an approval gate

# approval.py
import json, time, uuid

def request_approval(store, *, action, target_domain, data_preview, screenshot_path, reason):
    req = {"id": str(uuid.uuid4()), "ts": time.time(), "action": action,
           "domain": target_domain, "data": data_preview,
           "screenshot": screenshot_path, "reason": reason, "status": "pending"}
    store.save(req)          # e.g. a DB row that a review UI or chat bot shows to the approver
    return req["id"]

def wait_for_decision(store, req_id, timeout_s=3600, poll_s=5):
    deadline = time.time() + timeout_s
    while time.time() < deadline:
        req = store.load(req_id)
        if req["status"] in ("approved", "rejected"):
            return req["status"] == "approved", req.get("approver")
        time.sleep(poll_s)
    return False, None       # timeout = rejection

Record who approved, when, and what they saw. That record is your audit trail.

Worked example: a Dubai procurement assistant

A facilities company in Dubai lets an agent compare prices across three supplier portals and fill carts for routine consumables. The agent logs in through harness-injected, per-portal service accounts. It stops at checkout and posts an approval request to the procurement team's chat channel with screenshots and totals. Orders under a small threshold on a virtual card with a monthly cap are approved by any team member; larger ones need the manager. The agent never sees card numbers because the portal stores the company card and the human clicks "Place order" in the remote view.

Pitfalls

  • Approval prompts that say "Continue?" with no detail.
  • Approvals required for every trivial step, leading to rubber-stamping.
  • Storing session cookies unencrypted or sharing them across clients.

How to measure success

Track approvals requested, approval time, rejection rate (a healthy non-zero rate shows people are actually reviewing), secrets exposure incidents (target zero) and spend reconciled versus approved.

Key takeaways

  • Models should never see unneeded secrets or be the final authority on irreversible actions.
  • Prefer delegated tokens or human-in-the-loop login; if automation must log in, the harness fills credentials after an exact-domain check.
  • Default to 'agents prepare, humans pay'; if agents pay, use virtual cards, limits and agent payment protocols.
  • Approval gates must be specific, evidence-backed, code-enforced and risk-tiered to avoid approval fatigue.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. What is the safest way for an agent workflow to handle a portal login with MFA?
  2. Which approval request is best designed?
  3. Why is a zero rejection rate on approvals a warning sign?

Put it into practice

Classify every action in one of your agent workflows into tiers 0 to 3 and design the approval message for each tier-2 and tier-3 action.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.