Stay in control
ZeroSphere is built to make important actions visible and give you choices about access. The best setup is the one that matches the work you are asking it to do.
Protect provider keys
Provider keys are stored by the Electron desktop app using operating system backed protection when it is available. The app does not return saved key values to the visible interface.
Keep work inside the project
You can choose how ZeroSphere handles files outside the current project and files excluded by ignore rules. Start with Always ask if you are unsure.
Keep app access specific
Use App Use to decide when ZeroSphere may create a virtual screen, control your desktop, or open an app. Add trusted apps to Allowed apps and sensitive apps to Blocked apps.
Keep commands under review
Use Environment to decide when commands need approval. Add actions you never want the agent to run to the blocked command list.
Prefer a separate screen
Virtual screens give the agent a separate place to work. They are the usual choice when a task needs a Windows app.
If you allow real desktop control, watch the session. Physical Shift plus Escape is the emergency stop.
Stay realistic about safety
ZeroSphere can show what the agent is doing and ask before sensitive actions. It cannot make every website, file, tool, or model response safe automatically. Review unfamiliar work, especially when it touches accounts, private files, or external services.
Next, read Get help.