Security Center
Security Center is Aureink’s local protection on your computer, deciding “how far the AI can reach.” It gathers every action the AI takes — editing files, running commands, connecting to the network — into a single set of boundaries you can understand and adjust. Within it, the sandbox acts like a fence: the AI can only move inside the fence and can’t reach anything you haven’t allowed.
1 · Overview
Aureink runs tasks automatically within the scope you authorize, and Security Center is where that scope is drawn. It works through several layers: the Approval policy decides which actions must ask you first and which can go through; the Sandbox level decides which files the AI can change; Network access decides whether it can go online; plus protection for the workspace and sensitive directories, and the Audit Center that keeps a record of everything. Find it under Settings → Security Center.
Tip: The tighter the boundary, the safer; the looser, the more convenient. Use the defaults day to day; tighten up when handling sensitive content, and open things up as needed once you’ve run it through and come to trust it.
2 · Approval policy
The Approval policy decides “which actions need your nod.” There are three levels — pick based on how much you trust the current task:
〔Figure: Settings → Security Center, highlighting the three-level Approval policy switch〕
| Your scenario | Recommended policy |
|---|---|
| Handling sensitive data, important files, or using an unfamiliar capability for the first time | Strict — asks for your confirmation on each key action |
| Everyday office work and routine tasks, wanting both safety and efficiency | Recommended — auto-allows routine actions and only asks on risky ones (default) |
| Already fully trust the current task and want it done in one go | Loose — auto-executes most actions, blocking only a very few high-risk ones |
Delayed confirmation for dangerous operations: for irreversible or high-impact actions like deleting, overwriting, and bulk changes, even at a looser level Aureink gives you a confirmation step before executing, leaving room for you to call a halt — avoiding “one slip and it’s done.”
3 · Sandbox level
The Sandbox level decides “how much file permission the AI has” — that is, how big the fence is. There are four levels:
〔Figure: Security Center → the four Sandbox level choices〕
| Your scenario | Recommended level |
|---|---|
| Only analyzing, researching, or summarizing, without changing any files | Read-only — the AI can only look, not change |
| Need to produce files but worried about touching existing content | Workspace contained — operates in an isolated area without touching the rest of your workspace |
| Need normal read/write in the workspace and bulk file processing | Workspace write — can read and write your workspace (the common level) |
| A few advanced cases needing cross-directory or system-level operations | Full access — lifts the limits; enable only for fully trusted tasks |
Note: The higher the level, the wider the range the AI can touch. Follow “just enough,” and don’t leave it on Full access long-term for convenience.
4 · Network access
Network access decides whether the AI can go online, controlling whether data leaves your machine:
- Network disabled — the AI doesn’t access the network and data stays local, suitable for handling sensitive or confidential content.
- Controlled network — allows network access through a controlled proxy (such as online search, web scraping, or calling external services), with outbound behavior constrained by policy and recorded.
5 · Workspace and sensitive directories
- Workspace — the folder you authorize Aureink to read and write. The sandbox confines file actions here, and the AI won’t cross the boundary to touch anything outside the workspace.
- Sensitive directory protection — sensitive paths such as system directories and the locations of credentials and keys are protected by default; even when switched to a looser level, these directories get extra blocking to reduce the risk of accidental damage and leaks.
6 · Audit Center
Security starts with “being able to see.” The Audit Center keeps a complete record of what the AI does on your computer, making it easy to check and trace afterward:
〔Figure: the Audit Center event list, highlighting the search box, export, and clear entry points〕
| Event type | What’s recorded |
|---|---|
| Task | Which tasks were started and when they ran |
| Command | Which local commands were run |
| Network | Which outbound accesses occurred |
| File | Which files were read, written, or deleted |
| Approval | Which actions triggered a confirmation and how you handled them |
These records are searchable (locate by type / keyword), exportable (for archiving or compliance review), and clearable (to clean up local records).
7 · Important notes
Important notes
- Security tip: follow “enable only what’s needed.” The higher the level and permissions, the larger the risk surface, so be sure to tighten up when handling sensitive content.
- Permission boundary: the Approval policy, Sandbox level, and Network access together form the AI’s action boundary, and every capability’s operations (including Skills / Agents) are constrained by it and cannot exceed it.
- Care with dangerous actions: for irreversible operations like deleting, overwriting, and bulk changes, keep delayed confirmation and take a good look before allowing.
- Audit trail: the Audit Center’s records are stored locally; once cleared they can’t be recovered, so finish exporting for archiving before you clear them.
- Usage tip: run a new task under a tighter boundary first, then loosen as needed once you’ve confirmed the behavior matches expectations.
Disclaimer: Security Center is a protective measure running on your own machine, used to constrain the AI’s file, command, and network actions. Set the boundaries yourself based on data sensitivity and task trust, and keep exported audit records safe.
Last updated · July 2026 | Next: Advanced (Hooks · Local OCR · Interaction) →
