
It signs into a web backend, reads the data, makes the change you asked for, then re-opens the page to confirm it took effect. It only touches sites you put on the allowlist.
Sign in, read a table, change a price or stock level, submit a form — the everyday clicking-around work, done on instruction.
After every change it re-opens the page and reports what the page actually shows — no claiming success it can't see.
Operations are restricted to an explicit allowlist. Ask it to touch anything else and it refuses and tells you honestly, rather than guessing.
Big price swings, zeroing stock, or anything outside the sandbox become escalation cards — you approve in one click.