Definition

Rudder Desktop has a Built-in Browser for keeping web work beside the current Rudder surface. Ordinary web links can open in a Browser tab in the Side Panel, or the operator can choose the system browser. The website profile belongs to the current operating-system user and canonical Rudder instance. It is deliberately shared across organizations in that local instance, so signing into a site in one organization can leave the same site signed in after switching organizations. Agent control uses a different boundary. A supported local Agent Run receives only bounded Browser actions, and each controlled tab belongs to that exact organization, Agent, Run, and tab lease.

One illustrative case

A release Agent needs to check the public setup page before drafting an announcement. The operator is already signed in to the documentation provider through the shared Desktop Browser profile. During the Agent Run, the Agent opens its own tab, reads the published page, and captures a screenshot. It cannot read an operator tab or a tab leased to another run.

When it is useful

Use the Built-in Browser when a person wants web content in the Side Panel, or when an eligible local Agent needs audited navigation, reading, clicking, typing, or screenshots. The Agent Browser capability is available only in Desktop local_trusted mode for supported Claude, Codex, OpenCode, and Pi local runtimes while the instance setting is enabled. On macOS, the operator can import supported cookies from a selected Chrome, Edge, or Brave profile after confirming the instance-wide effect. The import does not include passwords, history, bookmarks, extensions, or downloads.

Operating boundaries

Operator link routing and Agent Browser access are separate settings. Choosing the system browser for operator links does not disable Agent tools. Disabling Agent access closes Agent tabs and removes later tool access, but preserves the operator tabs, shared website data, and saved link preference. The highest-risk boundary is the shared website identity. All organizations in one local instance share the profile, but no run gains broad access to that profile. Agents receive no cookies, passwords, arbitrary page scripts, raw CDP, or model-supplied identity. Clearing Browser data affects the whole local instance and requires explicit confirmation. See Permissions and platforms for the supported trust and platform boundaries.