Safe Sites Only.
An allow-list firewall for the agent's browser. Built for student use.
A browser-driving agent without limits is a problem. Safe Sites Only is the answer: J@rv1s can only navigate to domains, paths, and URL patterns that are explicitly on the allow-list. Off-list requests are refused, logged, and visible to the account guardian.
Every navigation request is checked. There is no "just this once" mode without explicit override.
Allow a whole domain, a single path, or a URL regex. Mix and match.
Every blocked attempt is logged with the requested URL and the reason.
Parents and IT see what's allow-listed, what's been blocked, and what's been visited.
Only the account owner can add to the allow-list. The agent cannot expand its own permissions.
Start with the recommended student preset, or build from scratch.
Add the specific URLs the student actually needs for school.
Refusal logs tell you what the agent tried to do that you didn't allow.
Add what's safe, refuse what isn't. The list is yours forever.
It can suggest. The owner approves. No silent expansion.
The check runs in under a millisecond per request. You won't notice it.