I'm building a companion island for my desktop AI assistant: approvals, a mascot, and a 14px wake strip
I'm building a desktop AI assistant, and it has a permission problem that no amount of prompt engineering fixes. Ankita asks for approval before it does anything irreversible — sends a message, runs a script, opens a browser session. That's the right behaviour. The problem is where that question appears: in the main chat window. Minimise the app, hide it to the tray, alt-tab to your IDE — and the…
This reporter is constructing a companion island for their desktop AI assistant, which addresses a permission problem that even prompt engineering cannot resolve. When the AI assistant needs to perform an irreversible action, such as sending a message or running a script, it must first obtain approval from the user before proceeding. The issue arises when the approval request appears within the main chat window, especially when the app is minimized or hidden.
To resolve this issue, the reporter is building a small, always-on-top companion island that appears when the main window is closed. This island has three views with fixed sizes: Petit tab, Home, and Home expanded. The island also includes a tucked view, which is a 14-pixel strip that can be hovered over to reveal the assistant. This 14-pixel strip is the core of the product's philosophy, as it allows for minimalistic interaction while still being visible.
The ApprovalRegistry, which stores pending approval requests, is a key component of the island. It stores each request individually, allowing the island to display all pending requests even if it is created after a request has been made. This prevents the approval request from appearing in the hidden main chat window while the assistant is waiting for approval. The expanded view shows the tool name and purpose, allowing the user to approve or deny the request without needing to restore the main window.
The island also features a small mascot with various states and animations, which helps to engage the user and make the assistant feel more personal. The mascot is created using the Coucou's Mochi engine, which has been adapted and re-skinned to fit the assistant's character. The mascot's animation engine reports a busy flag to indicate when everything has settled, ensuring a smooth user experience.
The reporter is also introducing two other significant changes alongside the companion island: Keyless Composio sign-in and MCP approval tiers. Keyless Composio sign-in uses a new OAuth 2.1 + PKCE flow that does not require a public URL or domain, making it more secure and easier to implement. MCP approval tiers introduce a four-level gate system that controls tool calls, ensuring that the assistant only asks for permission when necessary and does not grant unauthorized access.
In conclusion, the reporter is building a companion island for their desktop AI assistant to address permission issues and provide a persistent presence for the user. The island features three view sizes, a 14-pixel strip, and a mascot that engages the user. The reporter is also introducing two new features, Keyless Composio sign-in and MCP approval tiers, to improve security and user experience.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.