How Meta Muse Works: Secure VM, Sentinel and Approvals
Meta Muse runs each user's agent inside a dedicated cloud environment called Muse Secure VM. That design is central to how Meta positions the product's safety model.
Muse Secure VM
Every user gets an isolated virtual machine that holds the agent, connected data and the tools Muse uses, including its own browser. Meta describes this as a persistent, dedicated computer so the agent can continue multi-step work after the user closes the app.
Sentinel
A separate process named Sentinel sits on the same machine but is isolated at the system level from Muse. Meta states that nothing Muse attempts to send to the internet proceeds unless Sentinel approves it. This is the main gate for outbound network actions.
Credentials and payments
Muse is not supposed to read raw passwords or full payment card numbers. Credentials are held in secure storage the agent can invoke without viewing. For purchases, Meta points to Link by Stripe and one-time card numbers so the real card is not exposed to the merchant or the agent. Meta also states Muse is covered by Link purchase protections on eligible transactions.
User controls
Users choose which connectors to enable and the scope of access (for example read-only versus send). Sensitive actions such as sending email or completing a purchase are described as requiring approval. Users can review an audit trail and disconnect services. Training opt-out for model improvement is also mentioned in Meta materials.
Confidential VM (planned)
Meta has said a later Muse Confidential VM option would encrypt the environment with a key held only by the user. As of late September 2026 no general availability date is published.
Related: Muse Secure VM Explained, Privacy and Security, and the homepage overview.