Elevated risk is a warning ZeroTwo puts beside a few settings and screens where you would give it, or an app, more reach into your data. It is a flag, not a protection: the control still works once you switch it on, so the decision is yours. You will meet it in three places, plus one related warning.
Developer mode in the desktop browser settings
In the desktop app, a Developer mode card carries an Elevated risk badge: a small amber warning triangle followed by those words. Below it is a switch named Enable full CDP access. The card explains that the switch lets ZeroTwo run Chrome DevTools tools in a dedicated Chrome profile, including arbitrary JavaScript, network and console inspection, performance traces and browser control, and that this may expose sensitive browser data.
You can find the card in two places, both of which exist only in the desktop app:
- Settings > Browser, which manages ZeroTwo's built-in browser.
- Settings > Computer use, then Manage on the Google Chrome row.
The switch starts off. While it is off, ZeroTwo's browser agent cannot use its JavaScript tool on pages in the built-in browser, and it is told that "JavaScript execution needs Developer mode (full CDP access), which is turned off."
Always allow for website approval
Open Settings > Computer use and choose Manage beside Google Chrome. Under Permissions, the Approval row lets you choose whether ZeroTwo asks before it opens websites.
| Choice | What it does |
|---|---|
| Always ask | Ask before opening websites. |
| Always allow | Open websites without asking. An orange shield icon and the line "This setting has elevated risks for your data." appear under this choice. |
ZeroTwo starts with Approval set to Always allow, so if you would rather be asked first, change it to Always ask. The History, Downloads and Uploads rows beneath it offer Always allow, Always ask and Never, without that extra warning line. Further down, an Advanced switch named Allow all browser actions skips per-action approval and carries its own note that it can put your data at risk.
Connecting an app
When you connect an app that signs in through its own sign-in page, ZeroTwo first opens a window titled "Use app name in ZeroTwo" with a few notices. One is headed Apps may introduce elevated risk. It says that although ZeroTwo is built to protect your data, an attacker could try to go through ZeroTwo to your data in the app, or through the app to your data in ZeroTwo.
The next notice, Data shared with this app, says that by adding the app you let it access the basic information typically shared when you visit a website, such as your IP address and approximate location, plus a summary of your recent context and intent within ZeroTwo.
The same window has a switch, Reference memories and chats, which controls whether ZeroTwo may use relevant chats and memories when it shares data with that app. When you reconnect an app you already connected, or add a second account for it, ZeroTwo can skip this window and go straight to the app's sign-in, because you have already seen it. For the full flow, see Connect your apps to ZeroTwo with connectors and Control what ZeroTwo can do in a connected app.
A related warning: Full access
In the desktop app, a new Code or Work chat shows a permission picker in the message box, beside the + button. Its menu asks "How should ZeroTwo actions be approved?" and by default offers Ask for approval, Approve for me and Full access. Full access, described as unrestricted access to the internet and any file on your computer, is the only choice tinted orange. It does not carry the words Elevated risk; the orange tint is its only warning.
Deciding what to turn on
- Leave Enable full CDP access off unless you need ZeroTwo to inspect or script a web page.
- Switch Approval to Always ask if ZeroTwo will visit sites you do not control.
- Connect only apps you trust, and use Reference memories and chats only where you want that context to travel with your requests.