Ask Meta Muse to plan a trip, and it can work through a browser, fill in forms, and return for approval before a purchase. Ask it which terms your sales team promised a customer, and the answer depends on company records it has been given permission to see. So what can Meta Muse do today, and where does that access become the limit?
Key takeaways
- Meta Muse can send emails, book travel, shop, fill out forms, and work through longer personal projects, according to Meta’s launch announcement.
- It can keep working after you close the app, then ask for approval before sensitive actions such as sending an email or making a purchase.
- Its useful context comes from the personal services a user chooses to connect. A business task may require records, decisions, and permissions spread across a company.
- Meta has not presented Muse as a source-cited, permissioned company knowledge base. Giving an agent access to an app alone does not establish that it has the right evidence for a work decision.
Meta Muse is Meta’s personal AI agent, introduced in September 2026. A person can message it in the Muse app or WhatsApp, connect selected services, and ask it to carry out tasks using its own cloud-based browser. Meta says Muse can continue longer tasks in the background and request approval before sensitive actions. Its launch examples center on personal planning, communication, and purchases.
What can Meta Muse do today?
Muse’s clearest launch use cases are tasks with an identifiable goal and services the user can authorize. Meta’s announcement names sending email, booking travel, filling out forms, shopping, and planning toward longer-term goals. These are product claims and examples, rather than a guarantee that every booking or checkout will succeed.
Book travel and handle browser steps
Meta says Muse can open a browser, fill out forms, and book travel. A request such as “find a flight for Friday and book it” involves finding options, entering details, and pausing when payment approval is needed. The browser gives Muse a way to act across websites; it still needs the user’s preferences, access, and confirmation for sensitive steps.
Shop and make purchases with approval
Muse can shop and check out using Link by Stripe, according to Meta. Meta says Link’s wallet for agents uses a one-time-use card that hides the person’s actual card details from the agent. It also says Muse checks with the user before making a purchase. Shop Pay and 1Password support were described at launch as coming soon, so they should not be counted as launch capabilities.
Schedule, message, and organize personal plans
Muse can help coordinate time and resources for a goal, and Meta says it can send email with approval. Its example of a dinner party starts with a saved Instagram recipe reel: Muse turns it into a grocery list, suggests a menu, remembers friends’ dietary restrictions, and prepares invitations. That is a useful picture of the product’s intended scope, though Meta does not say that every scheduling service or invitation workflow is supported.
Early coverage gives other examples of the kinds of requests people are trying. Mashable describes users asking Muse to chase refunds, find cocktail bars, and turn saved recipes into cookbooks. Those reports show demand for practical errands; they are not evidence of a consistent success rate.
How does Muse carry out a multi-step task?
Muse works through connected services and a dedicated virtual machine with its own browser. Meta says its Muse Secure VM houses the agent and the data for services a person connects. Muse can continue a longer task after the app is closed, then return when something changes or approval is required.
The person chooses which services to connect and how much access to grant. Meta says email access, for example, can be limited to reading or extended to sending. It also describes a separate Sentinel agent that reviews what Muse sends to the internet, plus an audit trail showing actions taken and planned. These are Meta’s descriptions of its safeguards, not a reason to skip checking what access a connected account provides.
TechCrunch’s launch coverage reports built-in service connectors and says Muse can set up a connection to a service with a public API using credentials the user supplies. That broadens what an individual might connect. It does not, by itself, tell a business which employee should be allowed to read a particular customer record or act on it.
Where does Muse stop on work tasks?
The practical boundary is evidence and authority. Muse may be able to operate a browser or read a connected inbox, but a company question often has no reliable answer in one person’s account. Among AI agents, the ability to take action and the ability to justify a company-specific decision need separate evaluation.
Suppose a founder asks, “Can we promise Acme a Friday launch?” The answer might depend on a Salesforce deal note, a Slack thread about an engineering delay, and a signed agreement in Google Drive. If Muse only sees the founder’s email, it could miss the latest decision. If it can access more services through individual credentials, the business still has to determine which records it should see and whether the answer identifies its sources. Meta’s launch materials do not describe Muse as a company-wide, permissioned, source-cited knowledge base.
A second task is more consequential: “Email Acme to confirm the revised terms.” Muse’s approval check can give the sender a chance to review the email. It cannot supply missing contract terms or resolve a conflict between an old email and a newer signed document. The sender needs the relevant company evidence before approving the message. For a closer look at access decisions, see AI agent governance for business.
Privacy matters here too. Meta says people control connections and can disconnect services. In his account of using Muse, Inc. columnist Jason Aten describes concern that it read private messages he did not expect it to use. His experience does not establish how every account behaves, but it illustrates why a permission screen and a user’s expectations can differ. Start with the narrowest access a task needs, then inspect what the agent actually used.
How should a team decide whether Muse fits a task?
Use Muse for a personal task when the relevant services belong to the user, the request is specific, and the user can inspect sensitive actions before approval. For business questions, first identify where the answer lives and who may see each source. That check is more useful than assuming browser access equals company knowledge.
| Task | Likely fit for Muse | What to verify |
|---|---|---|
| Book personal travel | Meta describes booking and browser-based forms | Connected services, preferences, final price, approval |
| Build a grocery list from a saved recipe | Meta gives this as a launch example | Ingredients, quantities, dietary needs |
| Confirm a customer commitment | Depends on access to current company records | Signed terms, latest team decision, source permissions |
| Send a revised customer agreement | Muse describes email approval, but needs accurate inputs | Correct version, authorized sender, recipient, attachments |
For that last pair of tasks, a managed company brain built from selected business apps addresses a different need. Gyld indexes the company data a team chooses from apps such as Slack, Gmail, Google Drive, and Salesforce, applies private, team, or company-wide permissions, and makes source-cited knowledge available to compatible AI tools through MCP servers. There is no stated Muse–Gyld integration; Muse would need a supported way to use that context before the two could work together. Gyld’s comparison of company context approaches is useful if your team is deciding how to provide that evidence to agents it already uses.
The answer to “what can Meta Muse do?” is concrete: it can take on connected personal errands and pursue multi-step goals, subject to access and approval. For company commitments, test the evidence path as carefully as the action path. Ask where the current answer came from, who may see it, and whether the person approving the action can verify it.
Related reading
- Meta Muse review: What it does and where it hits a wall: A closer evaluation of the launch and its limits.
- AI agent governance for business: How to assign access and approval for work tasks.
- How to give AI agents real company context without fine-tuning: Options for making company knowledge available to an agent.
Frequently asked questions
Can Meta Muse book travel?
Yes. Meta lists travel booking among Muse’s launch capabilities and says it can use a browser and fill out forms. Check the itinerary and payment details before approving a booking.
Can Meta Muse buy things for me?
Meta says Muse can check out with Link by Stripe and asks for approval before making a purchase. Its launch announcement describes Shop Pay as coming soon, rather than available at launch.
Can Muse keep working after I close the app?
Yes, according to Meta’s launch description. Muse can continue longer tasks and return when something changes or it needs approval.
Can Meta Muse access my company’s Slack or CRM?
Do not assume a specific business connector or company-wide access from Muse’s personal-agent launch. TechCrunch reports that users can connect supported services and, in some cases, services with public APIs. A business should verify the available connection, its permissions, and the records Muse can actually use.
Does Muse cite the company records behind an answer?
Meta’s launch materials do not describe a company-wide, source-cited knowledge base for Muse. If a work answer depends on a contract, CRM record, or team decision, ask for the underlying source before acting.
Is Muse a fit for customer-facing work?
Muse may help with an action such as drafting or sending an email, with user approval. Customer-facing commitments also require current terms, authorized access, and a way for the reviewer to verify the evidence behind the message.
If your next task depends on company knowledge, start building your company brain with Gyld using the apps where that knowledge already lives.
