# DOM: Approval & Permission Dialogs > **Box is the main surface.** All operator work goes through Box (box.muse-dev.online). The web UI, `box` CLI, and agents share the same API endpoints. No UI-only powers. Companion to `DOM-APPROVALS-SPEC.md` (behavioral contract: detection → classification → handling → exit codes). This doc is the **DOM surface reference**: what the dialogs look like in the tree, which selectors find them, how `check_approvals` works today, and what's fragile. Related: `DOM-EDGE-STATES.md` §5.2, `DOM-PAGE-STRUCTURE.md` §3, `DOM-INDEX.md` §4f. ## 1. Observed specimen (real, from `docs/pip-approval-dialog.png`) Captured on pip's node during onboarding. This is a **Muse platform dialog rendered inside the chat DOM** (bottom-anchored card over the message stream) — not a browser-chrome permission bubble. ``` ┌─────────────────────────────────────────────────────────────┐ │ 🌐 Allow pip to share information with 34.139.37.135? │ │ ┌─────────────────────────────────────────────────────────┐ │ │ │ pip wants to connect to a remote server to complete │ │ (expandable detail, chevron) │ │ onboarding. ⌄ │ │ │ └─────────────────────────────────────────────────────────┘ │ │ [ Allow once ] [ Always allow this site ] [ Deny ] │ └─────────────────────────────────────────────────────────────┘ ``` | Field | Observed value | |---|---| | Title text | `Allow pip to share information with 34.139.37.135?` | | Title pattern | `Allow to share information with ?` | | Detail text | `pip wants to connect to a remote server to complete onboarding.` | | Detail pattern | ` wants to to .` (collapsible) | | Buttons (left→right) | `Allow once` (primary/blue), `Always allow this site`, `Deny` | | Icon | globe/network glyph preceding the title | Trigger class: the agent attempted an outbound network action (connecting to a remote server). Other trigger classes are **unobserved** — geolocation, camera/mic, notifications, clipboard, and download prompts have not been captured on fleet nodes yet (see §8 induction recipe). ## 2. Dialog DOM structure (as known) No `[role="dialog"]` or `[role="alertdialog"]` elements have been observed in settled-state probes (`DOM-PAGE-STRUCTURE.md` §3.2). The dialog is found **by text, not by structure** — this is the central fragility of the current implementation. Known structural facts: - The dialog is in-DOM (React-rendered), so `Runtime.evaluate` sees it; no shadow-DOM piercing has been needed so far. - Buttons are plain `