Skip to content

EthenEthenEthen

What We’re Building for Ethen Computer

Ethen Computer is a product direction within the Ethen Platform for supervised computer use: AI agents that operate websites and applications through their interfaces while a person can see what they are doing, approve consequential actions precisely, and stop or take over at any time. It is not a launched product, and this article does not announce availability, pricing or dates. What it does describe is the direction: visible sessions, bounded authority for each task, single-use approvals tied to one exact action, careful handling when an outcome is unclear, and completion backed by evidence. One part of that — how approvals bind to specific actions — has already been published in engineering detail. The rest is direction, and we explain what has to be true before Ethen Computer is offered more widely.

Ethen Computer is a product direction within the Ethen Platform for supervised computer use: AI agents that operate websites and applications through their interfaces while a person can see what they are doing, approve consequential actions precisely, and stop or take over at any time. It is not a launched product, and this article does not announce availability, pricing or dates. What it does describe is the direction: visible sessions, bounded authority for each task, single-use approvals tied to one exact action, careful handling when an outcome is unclear, and completion backed by evidence. One part of that — how approvals bind to specific actions — has already been published in engineering detail. The rest is direction, and we explain what has to be true before Ethen Computer is offered more widely.

Key takeaways

  • Ethen Computer is a direction, not a launch. It sits within the Ethen Platform and has no announced availability.
  • Supervision is the product. The goal is computer use a person can oversee, not an agent that runs unattended.
  • One mechanism is published. Approvals bind to one exact action, run and attempt, and can be used once.
  • Limits are stated, not hidden. Precise approvals do not make an agent resistant to manipulation by web pages.
  • Readiness depends on evidence, not a calendar. Wider availability depends on measured behavior and documented limits.

What is Ethen Computer?

Ethen Computer is Ethen's direction for computer use: letting AI agents operate software through its interface — seeing the screen, clicking, typing, navigating — on behalf of a person or a team. We explain what computer use is, and why it is harder than it looks, in Why Computer Use Is More Than Clicking Buttons.

The distinguishing idea is supervision. Many computer-use demos show an agent completing a task end to end with nobody watching. That is impressive, and for many real tasks it is not what organizations need. They need to know what the agent saw, what it did, who approved the steps that mattered, what happened when something went wrong, and whether the task was actually completed. Ethen Computer is being designed around those questions.

Ethen Computer belongs to the Ethen Platform, the part of Ethen aimed at teams and organizations running AI work with shared policies, approvals and records. It is distinct from Ethen Chat, Ethen Code and the other Ethen apps, each of which has its own focus, as we described in Why Ethen Is a Family of Specialized AI Apps. A product page for Ethen Computer will state availability and details when there is something available to state.

Where things stand today

The clearest way to describe status is to separate what is published, what is direction, and what we are not claiming. Figure 1 does that.

Three columns: published (highlighted) — approval binding and its stated limits; direction — visible sessions, bounded authority, stop and takeover, evidence-based completion; not claimed — availability, pricing, prompt-injection resistance, benchmark results.
Figure 1. What is public, what is direction, and what this article deliberately does not claim.

Published. We have published how computer-use approvals are bound to specific actions in Binding Computer-Use Approvals to Specific Actions. In short: an approval covers one exact action, within one run and one attempt, under the policy in force when it was requested, and it can be used once. That post is equally clear about limits. Precise approvals do not make an agent resistant to prompt injection, because injected content can influence which action is proposed without forging any approval. The post also makes no launch or availability claim.

Direction. Visible sessions, bounded authority for each task, immediate stop and takeover, careful handling of unclear outcomes and evidence-based completion are the design commitments described below. They describe what we are building toward. They are not claims that each is finished.

Not claimed. Availability, launch timing, pricing, supported applications, success rates and resistance to manipulation by web content are not claimed here. Where any of these become true and verified, they will be stated where they apply, with the evidence behind them.

We hold this line deliberately. Ethen's practice is to keep research, direction and shipped capability clearly separate, as we explain in Why Ethen Keeps Research Separate From Product Claims.

Five design commitments

Ethen Computer is being built around five commitments. Figure 2 summarizes them.

Five bands of design commitments: see, bound (highlighted), approve, recover and prove.
Figure 2. Five commitments that shape what Ethen Computer is being built to do.

See: sessions you can watch and review

A person should be able to watch an Ethen Computer session as it happens and review it afterward. That means seeing the screen the agent sees, the action it is about to take, the actions it has already taken and anything waiting for a decision. The agent's narration of what it is doing is useful, but it is not a substitute for seeing the screen, because narration can be wrong.

Review afterward matters as much as live viewing. Much computer-use work will run while people are doing something else. When they return, they should be able to understand what happened quickly, without replaying every step. The broader thinking behind this is in Designing Ethen for Work That Takes Minutes or Hours.

Bound: each task gets only the authority it needs

An agent filling in an expense report does not need access to your email. An agent gathering prices from public websites does not need to be signed in anywhere. The direction for Ethen Computer is that each task should carry only the authority it needs — which sites, which accounts, which kinds of actions — so that a mistake or a manipulated instruction has limited reach.

Ethen Research Lab has explored how a person's intent could be turned into bounded authority for an agent in Mandates: Compiling Human Intent Into Bounded Agent Authority. That is a research note, not a description of shipped behavior, but it reflects the direction: authority defined up front, so that approvals can focus on what falls outside it.

Approve: consequential actions, one at a time

Routine steps — reading a page, scrolling, searching — should not need a decision. Consequential steps — submitting, sending, paying, deleting, changing someone else's data — should. When a person approves, the approval should cover that exact action and nothing else.

This is the commitment with the most published detail, through the approval-binding mechanism described above. The reasoning behind keeping people in the loop for consequential actions is in Why Ethen Keeps Human Approval in the Loop.

A person should also be able to stop the agent or take over the session at any moment, and the agent should respect that immediately. After a person hands control back, the agent should look at the screen again rather than assume nothing changed.

Recover: unclear outcomes are treated as unknown

When an action's outcome is unclear — the page froze after "Submit", the connection dropped after "Pay" — the safe response is not to retry blindly. A blind retry can send a message twice or make a duplicate payment. The direction for Ethen Computer is to treat such outcomes as unknown, check the actual state where possible, and ask a person when it cannot be confirmed.

We describe this pattern in When an Agent Action's Outcome Is Unknown. It is also a reason recovery is a theme across Ethen, not only for Computer.

Prove: completion backed by evidence

An agent saying it finished is a claim. The direction for Ethen Computer is that completion should rest on evidence: a confirmation, a saved record, a sent message, a downloaded file. When evidence is not available, the status should say so plainly rather than reporting success.

What Ethen Computer is for

The tasks Ethen Computer is being designed for are ones where software has no suitable API, where the work is repetitive enough to be worth delegating, and where the steps that matter can be supervised. The following examples are illustrative; they describe the kind of work we have in mind, not supported workflows.

  • Gathering information across sites. Collecting prices, availability or public records from several websites into one summary, with the sources visible.
  • Working in systems without APIs. Updating records in an older internal tool that only has a web interface, with each change approved.
  • Preparing, not submitting. Filling in a long form — an application, a registration, an expense claim — and stopping for a person to review before submission.
  • Checking and reporting. Visiting a set of pages to confirm that information is current and reporting what has changed.

Some tasks are poor fits, and we expect them to stay that way for a long time: anything requiring judgment that a person would not delegate to a new colleague, anything where a single mistake is severe and irreversible, and anything where an API already does the job better. Computer use is a way to reach software that other methods cannot, not a replacement for those methods. Our thinking on actions that cannot be undone is in How Ethen Thinks About AI Actions That Can't Be Undone.

What has to be true before wider availability

Rather than a roadmap with dates, we think about readiness as a set of gates. Figure 3 shows them.

Four readiness gates: mechanisms in place; measured not assumed (highlighted), including adversarial pages; limits written down; and starting small.
Figure 3. Gates, not dates. The order reflects how we think about readiness, not a schedule.

Mechanisms in place. Supervision, precise approvals, stop and takeover need to work as designed, not as described.

Measured, not assumed. Behavior needs to be tested on defined tasks, including tasks with deliberately adversarial pages. Ethen Research Lab has published a benchmark design for exactly this kind of question — VerifiedWork Control, which sets out how delegation, approval, revocation and agent authority could be evaluated. It is a benchmark design with results gated, not a set of results. Ethen Research Lab's Synthetic Enterprise proposal describes an executable test world in which such evaluations could run. Neither is evidence that Ethen Computer meets any standard; both describe how we intend to find out.

Limits written down. What Ethen Computer cannot do, and the risks that remain, need to be documented as clearly as what it can do. Frameworks such as the NIST AI Risk Management Framework and the OWASP guidance on risks for large language model applications are useful reference points for that documentation.

Small first. Narrow tasks, close feedback and careful expansion come before wide use.

Questions we are still working through

Some design questions do not yet have settled answers, and we would rather name them than imply they are solved.

Where exactly is the line between routine and consequential? Submitting a search form is routine; submitting a job application is not. Many actions sit in between, and the line may differ by organization. We expect the default to be cautious and adjustable by policy.

How should sign-in work? Agents often need to act inside accounts. Entering credentials is something a person should control, and taking over the session to sign in is the conservative pattern. Making that smooth without weakening it is open work.

How much should a person have to watch? Live viewing is valuable for short, sensitive tasks and impractical for long ones. Good summaries and clear review points need to carry more of the load as tasks get longer.

How should results be reported to a team? When several people share responsibility for a task, approvals and records need to be clear about who decided what.

How Ethen Computer fits with the rest of Ethen

Computer use is one way for AI to act. Others include working through APIs and integrations, writing and running code, and producing documents and media. Ethen is organized so that each kind of work has a home suited to it. Ethen Computer is the home for supervised interface-level work in the Platform. Where an integration or API exists, other parts of Ethen are usually the better route; where none exists, computer use fills the gap.

The shared foundations — approvals, records, policies, and the principle that "done" needs evidence — are meant to be the same across Ethen. That consistency is part of what makes supervised computer use practical: the same approval habits and the same records apply whether an action comes from a computer-use session or another kind of agent work.

Tradeoffs and limitations

Supervision is slower than autonomy. Some tasks will take longer under Ethen Computer's model than with an unsupervised agent. We think that cost is right for work that matters.

Manipulation by web content is not solved. Bounding authority and approving consequential actions limit the damage; they do not prevent pages from influencing an agent.

Interfaces change. Agents that operate interfaces can break when those interfaces are redesigned.

This is direction. Design commitments describe intent. Until the readiness gates are met and documented, none of them should be read as a shipped capability.

FAQ

What is Ethen Computer? A product direction within the Ethen Platform for supervised computer use: AI agents that operate software through its interface while people can watch, approve consequential actions and take over.

Is Ethen Computer available? Not as a launched product. This article does not announce availability, and none should be inferred from it.

How is Ethen Computer different from other computer-use agents? Its design centers on supervision: visible sessions, bounded authority, single-use approvals tied to exact actions, careful handling of unclear outcomes, and evidence-based completion.

Does Ethen Computer prevent prompt injection? No approach fully does. Ethen's published approval mechanism makes approvals precise but does not make the agent resistant to manipulation by page content.

Where can I learn more? Start with Why Computer Use Is More Than Clicking Buttons and the engineering post on approval binding.

References

  1. Ethen Blog. Binding Computer-Use Approvals to Specific Actions. https://upcube.ai/blog/binding-computer-use-approvals-to-specific-actions
  2. Ethen Research Lab (2026). VerifiedWork Control: Evaluating Delegation, Approval, Revocation, and Agent Authority. Benchmark design; results gated. https://upcube.ai/resources/research/verifiedwork-control
  3. Ethen Research Lab (2026). Mandates: Compiling Human Intent Into Bounded Agent Authority. Research note. https://upcube.ai/resources/research/agent-mandates
  4. Ethen Research Lab (2026). Ethen Synthetic Enterprise: An Executable World for Enterprise-Agent Research. Research proposal. https://upcube.ai/resources/research/synthetic-enterprise
  5. National Institute of Standards and Technology (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. https://doi.org/10.6028/NIST.AI.100-1
  6. OWASP. OWASP Top 10 for Large Language Model Applications. https://owasp.org/www-project-top-10-for-large-language-model-applications/