Skip to content

Bounded power

Deep OS-level integration comes with greater responsibility.

That responsibility must be grounded in structural restraint.

Lynx AI prioritizes sandboxed execution whenever possible. Actions are scoped, isolated, and constrained by explicit permission boundaries.

Local execution does not imply unrestricted access.

Bounded capability is not weaker capability. It is the foundation of trust.


Structural constraints

Lynx AI cannot:

  • Access directories outside approved scope
  • Escalate privileges beyond granted permissions
  • Bypass macOS privacy mechanisms
  • Run hidden background processes without invocation

Power is deliberately contained.


Why it matters

Systems that operate close to the operating system must define clear limits. Without boundaries, local agents become indistinguishable from invasive software.

Lynx AI is powerful because it is constrained by design.