Your AI agent can write code, run tests and fix bugs. Ask it to use a real computer, and it hits a wall. It doesn't have permission.
Agents never get full control
A computer is built for a person in front of it, and it guards itself against everything else. So the moment an agent tries to do more than type in a terminal, the system stops and asks for a human:
- Accessibility access in Privacy & Security, before it can click and type.
- Screen Recording access, before it can see the screen.
- A password for sudo, or a Yes on Windows' User Account Control prompt.
- A dialog only a person can click.
That's how it should be. Your Mac should never hand full control to a program. But it means your agent can't finish on its own.
So you end up babysitting
You stay at the machine. You approve a permission, type a password, open Settings to allow one more thing, then wait for the next prompt. Or you set up remote login to do the same from somewhere else. Either way, the agent only works while you watch.
VMPal gives your agent a machine of its own
We built VMPal's virtual machines for this. Turn on agent control, connect your agent, and it gets everything a person at that desk has:
- The screen. It sees the machine's display directly. No Screen Recording permission.
- The mouse and keyboard. It clicks, drags, scrolls, types and uses shortcuts through the machine's own mouse and keyboard. No Accessibility permission.
- Administrator rights. It runs commands as the user or as an administrator. No sudo password, no User Account Control prompt.
- A direct line. It connects through VMPal. No SSH, no VNC, no remote desktop to set up.
You approve when you connect it. After that, your agent works on its own, and you don't have to be there.
Set it up
Open the machine's Settings › AI Agents and turn on Allow agent control of this VM. Then choose where your agent runs:
- Agent on This Mac. Your agent stays on your Mac and works the machine from there. Connect more machines, and it can use each of them. The machine just needs to be running.
- Agent Inside the VM. Your agent lives in the machine, with its own files and tools. Start the machine, sign in and install your agent there first.
Either way, click Add to Claude Code, or the button for Codex, Grok CLI or Gemini CLI. Restart your agent, give it a task and walk away.
In a macOS machine, connecting the first agent asks for the machine's administrator password.
Full control, on a machine that isn't your Mac
Full control is safe here because it's not your Mac.
- It only gets its machine. Never your Mac's screen, mouse or keyboard. Your files stay out unless you share a folder.
- You switch it on. Agent control is off until you turn it on, machine by machine. Turn it off, and the agent stops at once.
- You can undo. Take a snapshot before a big task, and revert if it goes wrong.
- You decide what it reaches. It sees only the network and folders you give the machine.
Download VMPal, make a machine and hand it to your agent. Then get on with your day.
