Skip to content

Build1 publisherNot yet confirmed elsewhere3 min readPublished

Four early adopters cut off Instinct and Meta's Muse over account access

Four early adopters told Business Insider they deleted or restricted Instinct or Meta's Muse over what the agents could reach in their accounts. Three of them still use agents, so their objection is to handing a company their inbox and logins.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Four early adopters cut off Instinct and Meta's Muse over account access
Generated illustration

What happened

  • YieldClub CEO Mahesh Vellanki deleted Instinct after a login attempt on his carrier account set off a two-factor prompt from an IP location labeled Iran.
  • Business Insider also reported user claims that agents read one-time Gmail login codes without asking and produced personal details from a document never sent.
  • Arcellx CEO Rami Elghandour now runs an agent he built on an open-source model on a Mac Mini, with access to his email, calendar and messages.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision A vendor that wants inbox access has to publish how its system was built safely, since Persinger set that explanation as his condition for connecting email to any assistant.
  • constraint Elghandour gives his own agent access he doubts he would give any company, so scoped permissions inside a hosted product do not settle his objection.
  • cost Elghandour deleted Muse over reports alone, with no personal accounts connected, so vendors lose users to incidents that remain unconfirmed.

Instinct says its assistant connects to email, messaging, screens, audio and location [4]. In August, the X account of Instinct founder and CEO Noah Shinn described an agent that users could reach by text message or phone call, one trained to operate a phone and a computer the way a human does [3][5]. I think the access complaints start with that design. An agent that works through a person's screens works through that person's logged-in sessions. A session carries whatever rights its owner has.

Scott Persinger, co-founder and CTO of BizTrip, found Instinct useful and deleted it anyway because he was not prepared to let the startup into his personal email [6]. He told Business Insider that much of his life could be exposed through password resets [6]. If reset links land in the inbox, an agent that reads the inbox can reopen accounts the user never connected to it. A settings page listing connected apps does not show that path.

Two-factor authentication runs into the same problem. Shinn said in a September 11 post that Instinct could draw on six-digit authenticator codes stored in its Vault, letting it carry on with a task past a login prompt [18]. RuntimeWire describes that as an intended, user-configured use of credentials [19]. A second factor exists so that a second thing has to agree to a login. When the agent holds the code, approval no longer needs the user. When the user does get a prompt, it cannot tell him whether the attempt came from his agent or from someone else. Instinct suggested Mahesh Vellanki's prompt reflected a benign IP-tagging issue, according to Vellanki, and he could not establish whether its systems had been compromised [10].

RuntimeWire says the four accounts do not establish that a breach occurred [17]. It also says the Vault feature does not verify the separate reports of agents reading Gmail codes without permission [19].

Every reason the four gave concerned access or data handling [2]. Vellanki still uses agents for less sensitive tasks and no longer gives them sensitive information [11]. Persinger still uses Muse and xAI's Grok Bot but connects neither to his inbox [7]. Guto Martino, co-founder of the open-source community Hermes Agents Brasil, deleted Instinct because he had no clear understanding of where his data went [15]. Rami Elghandour, chairman and CEO of Arcellx, deleted Muse after reports that it read users' texts without permission, though he had never connected personal accounts or data to it [12]. The agent with the widest access in this story is the one he built for himself [13]. He told Business Insider he was unsure he would grant that level of access to any company [14].

RuntimeWire's list of what users need has three parts: which accounts an agent can reach, which actions it may take and how to revoke that access [1]. A vendor can ship all three as settings. Four founders and executives are a small sample [2]. The report does not include deletion or retention figures, so it shows why these four pulled back and cannot show how many others have.

What to watch

  • Whether Instinct or Meta publishes how its agent stores and uses inbox access and saved authenticator codes, the explanation Persinger set as his condition.
  • Independent confirmation or refutation of the reports that agents read Gmail login codes and that Muse read text messages without permission.
  • Whether Instinct puts Vault code use behind a per-login user approval.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories