# What Mindset does not do

> Check the limits before you plan around Mindset, from browser automation and document handling to sign-in, environments, and experiments.

Read this page before you plan a rollout, so you know which jobs need another tool and which need a different shape.

## It doesn't find agents you don't know about

If someone builds an agent in Claude, ChatGPT or Copilot Studio and connects it straight to a system, Mindset never sees it. Finding those belongs to your tenant admin tooling, your data loss prevention, and your threat detection.

The two work together. Discovery tells you an agent exists. Mindset is the record of what its agents were allowed to do and what they did. An agent your discovery tools find that has no record in Mindset reached its system some other way, and that gap is the finding.

## It doesn't drive a browser

There's no browser automation, screen scraping, or computer use. An agent reaches an outside system only through an operation on a [connection](https://docs4.mindset.ai/docs/ams/connect-a-system). If a system can only be used through its screens, that automation stays where it is until the system has an API, a database, a sheet, or an MCP server.

## It doesn't pass documents to the model

An agent can see images. PDFs, spreadsheets, logs, and other documents don't reach the model as content. A connection can fetch a file and send it on to a service you connect, such as a text extraction service, and the agent reads what that service returns.

## It doesn't hold each call for approval

Approval is per operation, and it happens once. After a write operation is enabled, every call to it runs. If a person must look at each individual change, an author builds that into a [script](https://docs4.mindset.ai/docs/ams/write-a-script) as an ask phase, and the run waits for the answer. An agent can never approve an operation.

## It doesn't give each agent its own login at the outside system

Mindset's audit records which agent acted. The outside system sees the connection's shared credential (or, with StackOne, the end user's). It can't tell your agents apart.

## It doesn't replace your identity or access tooling

Who may use which model, who is licensed, and who is in which group stay where they are today. People sign in to Mindset with a Google account or an email address and password. Microsoft sign-in isn't available. Mindset governs what an agent may do once it exists.

## It doesn't copy work between environments

Nothing moves from one [environment](https://docs4.mindset.ai/docs/ams/environments) to another on its own. Promoting a change means making it again in the other environment. You can't delete an environment once it exists.

## It doesn't split live traffic between versions

Experiments run offline. You compare versions of an agent against the same test set, and no arm of an experiment serves real users. There's no A/B split of live traffic.

## It doesn't reach Microsoft Teams

Agents reach people through the Hub, an element embedded in your own product, or MCP. There's no Microsoft Teams surface.

## It doesn't sit in front of agents you wrote in code

Mindset runs the agents you build in it. It isn't a gateway for model calls from agents that live in your own codebase.

## It doesn't define the work for you

If nobody has written down what the work is and what a good result looks like, Mindset won't work it out. The three questions in [Will your automation work here?](https://docs4.mindset.ai/docs/ams/will-your-automation-work-here) tell you whether something is ready.

## Runs can wait, and they resume

A script's ask phase parks the run until a person answers, then the run carries on. Set the phase's wait limit so a run doesn't wait forever when nobody answers. If the worker carrying a run stops, the run is picked up again. See [Limits and run behavior](https://docs4.mindset.ai/docs/ams/limits-and-run-behavior).
