In Meta's Muse personal-agent architecture, Sentinel is a separate process from the main agent and is the sole authority for connector allow/deny/ask-user decisions and for every byte of egress leaving the per-user Secure VM, inspected at L4 and L7 and enforced at the kernel. A coarse user grant such as Allow Always can still authorize outbound Marketplace messages that include a pickup address the user typed into a reply template — Sentinel brokering that grant is not the same as field-level least privilege or a per-send consent gate on contact data.