DocsAgents & automations
Operator
Most apps give the assistant dedicated tools - a real "create a note" or "add an event" action. Operator is the fallback for everything else: it lets the assistant open a window, read what's on screen, and click, type, select, scroll, or press keys inside it, the same way you would with a mouse and keyboard.
When it's used
Ask for something an app has no dedicated tool for - "fill in this form the way I usually do it," or "open Settings and turn that on for me" - and the assistant reaches for Operator on its own. You don't need to ask for it by name.
The first time
The first time the assistant wants to operate a particular app, it asks: "Let the assistant operate <App>?" Say yes and it remembers for next time; say no and it won't try again without asking. You can change your mind either way at any point - a decline isn't permanent, and you'll simply be asked again the next time it would help.
While it's working
A small "Operator is acting" banner appears at the bottom of the screen with a Stop button, so you always know when the assistant is driving a window rather than just answering in the strip. Stop cancels the whole run immediately.
Approval for anything irreversible
Clicking something that looks irreversible - Delete, Send, Submit, Sign out, and similar - pauses for your approval first, exactly like any other action that can't be undone. Typing into a field or selecting an option never needs approval on its own; only the moment something is actually committed does.
What it can't do yet
Operator can see and act inside built-in apps and the ones you've made or installed as native apps. It doesn't yet reach inside a sandboxed app installed from a source outside this OS, or a canvas-only app like a game (screenshots of those work, when there's a picture to take, but clicking around inside them doesn't). If you ask for one of those, the assistant will say so plainly rather than pretend it worked.