# Small Business AI Workflow Starter Version: October 4, 2026 Companion: https://jwatte.com/blog/desktop-commander-cowork-browser-agents-small-business/ Server guide: https://jwatte.com/downloads/sovereign-ai-setup-guide.md This is a project brief and acceptance checklist, not permission for an agent to administer every business account. The examples describe fictional businesses. Use redacted copies of your own approved material. Never put API keys, passwords, browser cookies, customer payment data, door codes, or recovery secrets in this file. ## 1. Pick one result Write a one sentence deliverable, such as: Produce tomorrow's repair queue from the approved job export, with missing parts and conflicting dates listed separately. Owner: REPLACE_WITH_OWNER Reviewer: REPLACE_WITH_REVIEWER Allowed input folder: REPLACE_WITH_INPUT_FOLDER Allowed output folder: REPLACE_WITH_NEW_OUTPUT_FOLDER Approved public URLs: REPLACE_WITH_EXPLICIT_URL_LIST Deadline: REPLACE_WITH_DEADLINE Cost limit: REPLACE_WITH_BUDGET Cloud processing permitted: YES_OR_NO Human approval required before sending, buying, deleting, publishing, or committing to a customer: YES ## 2. Create an isolated pilot folder On Linux or macOS, run from the location where you keep projects. This creates a new folder and refuses to replace an existing pilot. ```bash set -eu pilot="$HOME/ai-workflow-pilot" if [ -e "$pilot" ]; then printf '%s\n' 'Existing pilot retained. Choose a new directory.' >&2 exit 1 fi mkdir -p "$pilot/input-approved" "$pilot/output-drafts" "$pilot/evidence" "$pilot/review" "$pilot/scripts" printf '%s\n' '.env' '.env.*' 'credentials/' 'sessions/' 'private-originals/' > "$pilot/.gitignore" printf '%s\n' 'Read input-approved. Write only output-drafts, evidence and review. Ask before any external action.' > "$pilot/AGENTS.md" printf '%s\n' 'Pilot folder created. Copy only approved, redacted material into input-approved.' ``` For Windows, use a new folder in File Explorer with these same subdirectories. Do not run a Unix shell block in an ordinary PowerShell prompt. A .gitignore is not a data loss prevention system. Review every file before committing. ## 3. Choose the right access route Use a document task workspace for a deliverable assembled from documents. Use a browser connection for a task that genuinely needs a website. Use a terminal tool for reproducible file operations, tests, or deployment scripts. Authorize each separately. A browser extension does not create a server connection. Provider starting points, checked October 4, 2026: | Provider | Task or browser starting point | Terminal starting point | |---|---|---| | Anthropic | Claude tasks/Cowork and Claude in Chrome | Claude Code | | OpenAI | ChatGPT Work and the browser integration offered in the desktop app | Codex CLI | | Google | Eligible Gemini Spark and Gemini in Chrome accounts | Gemini CLI | | Kimi | Kimi Claw, Kimi Browser Extension, Kimi Code Desktop | Kimi Code CLI | | Microsoft | Copilot Cowork and supported Edge work features | Select a separate approved development tool | | Perplexity | Computer, Personal Computer, Comet | Follow the supported host instructions; do not assume Ubuntu support | | Manus | Manus tasks and Browser Operator | Browser access alone is not a server shell | | Local models | Open WebUI for an explicitly configured local model | Aider or another explicitly connected tool | Do not treat this table as a claim that every product runs on every operating system. Record the exact plan, version, platform and feature you verified. Write "no direct equivalent verified" for gaps. Install Chrome extensions only from the store links in the publisher's instructions. Test one public page first. Confirm the browser profile and site permissions. Keep banking and personal profiles outside the pilot. Use one agent at a time in each task tab. Official starting points: - Claude in Chrome: https://support.claude.com/en/articles/12012173-get-started-with-claude-in-chrome - Cowork execution locations: https://support.claude.com/en/articles/15520349-use-claude-cowork-on-web-desktop-and-mobile - ChatGPT browser extension: https://learn.chatgpt.com/docs/chrome-extension - Gemini in Chrome: https://support.google.com/chrome/a/answer/17030585 - Gemini CLI: https://github.com/google-gemini/gemini-cli - Kimi Browser Extension: https://www.kimi.com/en/help/kimi-webbridge/kimi-webbridge-faq - Desktop Commander remote setup: https://github.com/wonderwhy-er/DesktopCommanderMCP/blob/main/src/remote-device/README.md ## 4. Test the connection before giving it work For a terminal connection, ask it to show the hostname, current directory, and names in your pilot folder. Check those against the intended machine. Save a harmless draft into output-drafts and read it back. Do not ask for environment-variable values or credential files. For a browser connection, ask for the title and URL of one approved public page without clicking anything. Then authorize one reversible action on a test page. Keep account approvals and any verification codes in the provider's own UI. A device can be registered but unreachable. Verify an actual command, not only a green installation label. Keep an independent SSH or recovery route for a server. ## 5. Three project briefs ### Bicycle repair shop Input: Redacted job export, approved parts list, and three approved supplier URLs. Prompt: > Draft tomorrow's repair queue using job references, not customer names. Preserve deadlines and note contradictions. Separate confirmed parts, missing parts and unknown availability. Record the source URL and check time for supplier information. Save the queue and evidence into the pilot output folders. Do not place orders, contact customers, change bookings or promise collection times. Acceptance: Every input job appears once. Missing fields remain marked missing. A blocked supplier page is reported as unknown. The owner reviews priorities and commitments. ### Event catering business Input: Five redacted inquiries, approved menu, portion rules and price sheet. Prompt: > Draft one proposal packet per inquiry using only the approved menu, price sheet and portion rules. Flag missing dates, guest counts and dietary questions. Show the calculation behind each quantity and price. Do not infer ingredient safety, make substitutions, email proposals, accept deposits or change orders. Save drafts and a separate unresolved-questions list. Acceptance: Arithmetic is independently checked. Dates and quantities cite their inputs. A qualified staff member resolves dietary questions. Generated artwork is marked conceptual and is not represented as a photo of actual food. ### Commercial cleaning company Input: Approved schedule, redacted completion export and supply notes. Exclude alarm codes, entry instructions, employee health information and personal contact details. Prompt: > Compare scheduled job IDs with completion records. List missing jobs, supply exceptions and notes requiring a supervisor's review. Quote the supporting source text. Group the draft handoff by site reference. Do not change shifts, message staff, modify building access instructions, mark work complete or make employee performance judgments. Acceptance: Missing IDs are found by a deterministic comparison. Duplicates are visible. The supervisor checks false alarms and decides what to do. ## 6. Review before automation For each output record, save the input reference, source excerpt, result, missing-field list and reviewer decision. Preserve the original source separately. Do not replace it with an AI summary. Record at least ten representative pilot jobs before evaluating convenience. Include an intentionally missing field, contradictory date, duplicate reference, unreachable page and an input containing instructions that conflict with the brief. Do not use customer emergencies as test cases. | Run | Input count | Missing jobs | Incorrect fields | Review minutes | External cost | Approved by | |---|---:|---:|---:|---:|---:|---| | Pilot 1 | | | | | | | | Pilot 2 | | | | | | | | Pilot 3 | | | | | | | Success means a reviewed business output with less total effort. More generated text is not success. Stop if corrections take longer than the existing process. ## 7. Optional component decision record | Component | Add only for this need | Required check before use | |---|---|---| | Cloudflare Tunnel and Access | Authenticated browser access to private services | Allowlisted identity succeeds; unauthorized identity and direct-origin bypass fail | | Tailscale | Private connectivity between enrolled devices | Device identity and access policy verified | | Browser desktop | Persistent server-side work browser | Authentication, workspace mounts and extension platform support reviewed | | Deno | An existing Deno project | Locked runtime and project tests pass | | Vercel CLI | A Vercel-hosted project | Correct account/project and preview verified | | PM2 | An existing Node service using PM2 | No competing Docker/systemd supervisor | | Gitleaks | Precommit secret review | Findings triaged; no blanket suppression | | Trivy | Package and image vulnerability review | Relevant findings addressed or explicitly accepted | | Figma integration | Maintained design source | Approved file access and intended write scope | | Ideogram | Conceptual artwork | Nonconfidential prompt, cost approval and image review | | Qdrant | Retrieval across a substantial document collection | Embedding choice, provenance and retrieval tests | | n8n | A stable repeatable workflow | Retry safety, duplicate prevention and failure ownership | Restic handles encrypted recovery snapshots. Rclone handles deliberate transfer or synchronization. Keep backup credentials independent of the retiring computer and record a successful restore, not merely an upload. ## 8. Shared remote access without a public command box A mobile directory may link to a prompt portal, browser desktop, code editor, chat UI and gateway administration. Protect every destination, not only the directory. Never place a password in a URL or HTML file. Use a proper shared identity layer where supported instead of repeating one valuable password across unrelated providers. The prompt box should propose a known operation before execution. Keep arbitrary shell access in a separately protected terminal with explicit approvals and a non-root account. Email OTP verifies access to a mailbox; it does not verify that a proposed command is safe. ## 9. Pilot sign-off - [ ] Inputs are approved and redacted. - [ ] The correct device and browser profile are verified. - [ ] Read, draft and reversible-edit tests pass. - [ ] External actions require explicit approval. - [ ] Failures and unknowns remain visible. - [ ] Model/API billing is explicit, with no silent fallback. - [ ] A person has reviewed the outputs against the source. - [ ] Recovery and an independent access route have been tested. - [ ] A named owner approves adding a schedule or production deployment. This kit is a starting point. It does not grant consent on behalf of customers or certify a deployment.