# 7.5 Prefer connectors to browsers, and browsers to screen control (/managing-ai-workers/the-authority-envelope/connectors-browsers-screens)

---
type: Document
title: "7.5 Prefer connectors to browsers, and browsers to screen control"
description: "Three ways a worker can reach a system, how they differ in reach, record and control, and which to choose."
status: stable
order: 207.5
ksor:
  owner: team:panaversity
  audience: [ public ]
  approval:
    by: process:panaversity
    at: 2026-10-06T21:02:42Z
chapter: "07"
part: II
expert_status: required
concepts: [ "7.5" ]
last_verified: 2026-10-07
generated:
  at: 2026-10-06T21:02:42Z
  by: esl-rewrite/1.2.0+ksor.1
trust_tier: unverified
build_id: sha256:c93b28093c2f70c60faae2645a693d881b657ff94d00f7dd9f8c06427ff61c87
dirty: true
ksor_version: 0.0.60
---

**In everyday life.** To pay a bill, you can use the company's app, log in on its website, or hand someone your unlocked laptop.

An AI Worker can reach another system, such as an accounting system, in three ways.

**A connector** is a link to one system that offers named actions through the system's own interface. Each named action is a tool. Reading and writing are separate tools. Each call to a tool can be approved and recorded one by one.

**A browser** uses web pages the way a person does. It can reach any site. If it is signed in, its session carries the person's full rights: everything that person may do on the site. And its clicks are harder to review than named tool calls.

**Screen control** uses desktop apps by looking at the screen, moving the pointer and typing. Anthropic calls it computer use. It reaches anything visible, including windows you did not mean to show.

Order them by how narrow the reach is, how clear the record is, and how the permissions are enforced. Connectors usually come first, but not always. A connector with every tool switched on can reach more than a browser signed in to an account with few rights. So use the narrowest well-controlled path. That is usually a connector, then the browser. Use screen control only for a trusted app that has no other way in, with sensitive windows closed.

Browser and screen actions skip a connector's own limits, such as which tools are on and which ask first. The application still checks the rights of the signed-in account. But those are a person's rights, usually wider than the worker needs. So rebuild the limits around them yourself, with approval for each app or site and a record of what was done.

![The title reads "Choose the narrowest path with effective controls." The line below it reads "Usually: connector first, browser next, screen control last." A table compares three routes in four rows: reach, action record, permissions, and how to use it well. Connector, usually first: it reaches the named actions the connector exposes. Its action record is structured tool calls, and logging and approval depend on setup. Its permissions are tool restrictions plus the connected account's rights. To use it well, enable only the tools and data the task needs. Browser, when a connector cannot do the job: it reaches allowed sites and accessible signed-in sessions. Its record is page interactions and clicks, so inspect the available logs. Account and browser controls apply, but connector limits do not. To use it well, restrict sites, use a limited account and require needed approvals. Screen control, when no narrower route works: it reaches accessible apps, windows and desktop content. Its record is clicks, typing and screen observations, which are often harder to audit. Account, operating-system and app controls apply, but connector limits do not. To use it well, use trusted apps, close sensitive windows and record actions. A gold note says to compare the actual setup, because a broadly privileged connector can reach more than a tightly restricted browser account. A dark bar reads: check reach, action records and enforceable permissions before choosing.](img/tool-order.png)

*Figure 7.5. Three ways to reach a system, compared by reach, record and permissions.*
