Web access
Choose which sites Titan AI can reach, and understand what that setting does and does not cover.
Titan AI can read the open web when it needs to, not just your Amazon data. Web access, on the Web Access tab in Settings, is where you choose how far that reaches.
There are three modes. Restricted is the default for new accounts.
This is a control over which sites Titan AI can reach. It does not make reading a page safe by itself, and it is not a defense against a page that tries to manipulate Titan AI while it is there. Read what a narrower list does and does not cover before you rely on it.
The three modes
| Mode | What it means |
|---|---|
| Off | Titan AI cannot reach the web at all. It works only from your Amazon data and anything you share with it directly in chat. |
| Restricted (default) | Titan AI can reach the domains on your list below, whether it fetches a page directly or opens it in a browser. The browser path has one narrow exception, covered under Browser automation. |
| Full access | Your list does not apply. Titan AI can reach any site on the web. What that means for the browser is covered under Browser automation. |
Off and Restricted apply the moment you pick them. Full access is different: it turns off a protection rather than narrowing or holding one, so choosing it opens a confirmation first, naming what it turns off. Nothing changes until you confirm.
Your domain list
The list below the mode picker is what Restricted mode enforces. Add a domain by typing it and pressing Enter or Add; remove one with the X next to it. Some entries are marked Managed and cannot be removed, these are on the list by default so Titan AI can do basic work out of the box.
You can write an entry three ways:
| You write | It matches |
|---|---|
example.com | That exact site, nothing else. |
*.example.com | Its subdomains only, not example.com itself. |
**.example.com | The site itself and every subdomain. |
Most sites move you from the plain name to the www address the moment you
arrive, and an entry for the plain name does not cover that second address. So
example.com on its own can still fail to open, even though it looks like the
site you asked for. **.example.com is the entry that covers both, which is
why it is the form to reach for when you are adding a site you want to browse.
If you do hit this, Titan AI will tell you that a redirect is what stopped it,
so you know to reach for the **. form rather than guessing.
You do not need to remove the narrower entry first. Adding the wider one is enough, and it works the same way for an entry marked Managed, which you cannot remove.
The list has no effect while web access is Off, and no effect in Full access, since neither mode enforces it.
Add the sites you need Titan AI to reach. A few kinds of entry are never
allowed, such as a wildcard over a whole domain ending like .co.uk, or an
IP address. If one is refused you will be told why.
Browser automation
When web access is on, Titan AI can also open a page in a browser and take a screenshot, not only fetch it directly. It can click and type on the page too, the same way you would, not only look at it. That is a separate path from the direct fetch described above, and your mode changes what it means for that path.
On Full access, the browser is unrestricted, same as everything else in that mode. There is no list to apply, so it can open any page.
On Restricted, the browser is held to your list just as strictly as your direct fetches are, with one exception. The browser gets no network access of its own: everything it loads, including the resources a page pulls in and anywhere a redirect sends it, goes through a filter built from your list, so a host off your list does not load. The exception is deliberate: two Amazon image sites that Amazon's own pages need in order to display are allowed alongside a listed Amazon host, even though they are not shown in your list. Without them a real Amazon page renders with no product images at all.
What this setting does and does not cover
Restricted mode governs the pages Titan AI loads, whether it fetches them directly or opens them in a browser: opening a URL, reading a page, following a link. It does not cover everything else Titan AI can do on the web, and it is worth knowing the difference before you trust the list as a complete boundary. The Browser automation section above covers the browser path and the one exception that applies to it.
Web search is a separate channel. Restricted mode's list does not limit what a search can return. If Titan AI searches the web on your behalf, the results it gets back can come from any site, not only the ones on your list. Treat anything that comes back from a search the same way you would treat a result from any other search engine: read it, do not assume it was pre-filtered to your list.
That is not a bug in your setting: Off still turns off all web access, including search, and your Restricted list still does exactly what the table above says. The point is narrower than "Titan AI can only see these sites." It cannot reach outside your list, whether by fetching or by browsing, but it can still encounter other sites through search results.
Restricted mode shrinks how much of the web Titan AI can be pointed at, and that is real protection. It is not a promise that everything it reads is trustworthy, and it is not a defense on its own against a page written to try to manipulate an AI reading it. Treat what Titan AI reads off the web the way you would treat an email from someone you don't know: useful, but not automatically believed.
Titan AI