# What does the Elevated risk label mean in ZeroTwo?

> ZeroTwo flags a few desktop browser settings and the app-connection window with elevated-risk warnings. Here is where they appear and what to weigh.

Source: https://help.zerotwo.ai/en/articles/20001062-what-does-the-elevated-risk-label-mean-in-zerotwo
Section: Privacy and policies
Last updated: 2026-10-05

Elevated risk is a warning ZeroTwo puts beside a few settings and screens where you would give it, or an app, more reach into your data. It is a flag, not a protection: the control still works once you switch it on, so the decision is yours. You will meet it in three places, plus one related warning.

## Developer mode in the desktop browser settings

In the desktop app, a **Developer mode** card carries an **Elevated risk** badge: a small amber warning triangle followed by those words. Below it is a switch named **Enable full CDP access**. The card explains that the switch lets ZeroTwo run Chrome DevTools tools in a dedicated Chrome profile, including arbitrary JavaScript, network and console inspection, performance traces and browser control, and that this may expose sensitive browser data.

![The Elevated risk badge on ZeroTwo's Developer mode card: an amber warning triangle followed by the words Elevated risk, above the Enable full CDP access switch](https://help.zerotwo.ai/images/privacy-and-policies/20001062-elevated-risk-labels/01-elevated-risk-label-with-orange-warning-icon.png)

You can find the card in two places, both of which exist only in the desktop app:

- **Settings > Browser**, which manages ZeroTwo's built-in browser.
- **Settings > Computer use**, then **Manage** on the **Google Chrome** row.

The switch starts off. While it is off, ZeroTwo's browser agent cannot use its JavaScript tool on pages in the built-in browser, and it is told that "JavaScript execution needs Developer mode (full CDP access), which is turned off."

## Always allow for website approval

Open **Settings > Computer use** and choose **Manage** beside **Google Chrome**. Under **Permissions**, the **Approval** row lets you choose whether ZeroTwo asks before it opens websites.

| Choice | What it does |
| --- | --- |
| **Always ask** | Ask before opening websites. |
| **Always allow** | Open websites without asking. An orange shield icon and the line "This setting has elevated risks for your data." appear under this choice. |

ZeroTwo starts with Approval set to **Always allow**, so if you would rather be asked first, change it to **Always ask**. The **History**, **Downloads** and **Uploads** rows beneath it offer **Always allow**, **Always ask** and **Never**, without that extra warning line. Further down, an **Advanced** switch named **Allow all browser actions** skips per-action approval and carries its own note that it can put your data at risk.

## Connecting an app

When you connect an app that signs in through its own sign-in page, ZeroTwo first opens a window titled "Use *app name* in ZeroTwo" with a few notices. One is headed **Apps may introduce elevated risk.** It says that although ZeroTwo is built to protect your data, an attacker could try to go through ZeroTwo to your data in the app, or through the app to your data in ZeroTwo.

The next notice, **Data shared with this app**, says that by adding the app you let it access the basic information typically shared when you visit a website, such as your IP address and approximate location, plus a summary of your recent context and intent within ZeroTwo.

The same window has a switch, **Reference memories and chats**, which controls whether ZeroTwo may use relevant chats and memories when it shares data with that app. When you reconnect an app you already connected, or add a second account for it, ZeroTwo can skip this window and go straight to the app's sign-in, because you have already seen it. For the full flow, see [Connect your apps to ZeroTwo with connectors](https://help.zerotwo.ai/en/articles/11487775-connect-your-apps-to-zerotwo-with-connectors) and [Control what ZeroTwo can do in a connected app](https://help.zerotwo.ai/en/articles/20001495-control-what-zerotwo-can-do-in-a-connected-app).

## A related warning: Full access

In the desktop app, a new Code or Work chat shows a permission picker in the message box, beside the **+** button. Its menu asks "How should ZeroTwo actions be approved?" and by default offers **Ask for approval**, **Approve for me** and **Full access**. Full access, described as unrestricted access to the internet and any file on your computer, is the only choice tinted orange. It does not carry the words Elevated risk; the orange tint is its only warning.

## Deciding what to turn on

- Leave **Enable full CDP access** off unless you need ZeroTwo to inspect or script a web page.
- Switch **Approval** to **Always ask** if ZeroTwo will visit sites you do not control.
- Connect only apps you trust, and use **Reference memories and chats** only where you want that context to travel with your requests.
