# A Comet browser review for business teams

> This Comet browser review tests its assistant, privacy model, business workflows, security tradeoffs, and the work it can genuinely speed up.

Comet earns a place in a business pilot when people spend hours reading across tabs, turning web material into a first draft, or doing repetitive work inside browser tools. Its Assistant can inspect the page in front of you, work across selected tabs, search browsing activity, and take supervised actions such as clicking, typing, and filling forms. That is a meaningful change from opening a chatbot in another window and pasting fragments into it.

It does not earn a blanket rollout simply because the demonstrations look fast. The same context that makes an AI browser useful can include customer records, internal dashboards, email, calendars, and authenticated sessions. A business has to decide which sites the Assistant may read, where it may act, which outputs need human verification, and whether the consumer or Enterprise data terms fit the work. My verdict is favorable for research and low risk browser administration, conditional for email and form workflows, and negative for unsupervised actions that can move money, publish data, or change production systems.

## Comet is an assistant inside a Chromium browser

Comet feels familiar because it is based on Chromium and supports standard browser functions, including bookmarks, page translation, and most Chrome extensions. The material difference is the Assistant in the sidebar. It can use the current page as context, summarize long pages and PDFs, answer questions about selected text, compare information across chosen tabs, and interact with websites when a task calls for action.

That placement removes a small but persistent tax. In a separate chatbot, the user copies text, explains where it came from, switches back to check a detail, then repeats the cycle for the next tab. In Comet, the browser already knows which page the user means. The `@tab` reference can narrow a request to a named open tab, which matters when a window contains unrelated customer, finance, and personal pages.

The Assistant is not a second pair of eyes with perfect access to everything. Perplexity's Comet Assistant privacy documentation says it does not upload the full list of open tabs, browsing history, cookies, passwords, local files, or text entered on websites by default. It sends context when a request requires that context, such as summarizing the current page, reading selected text, using a referenced tab, or completing an email or calendar task.

This distinction changes how I judge the product. Comet is strongest when the requested context is obvious and bounded: "Compare the warranty terms in @Supplier-A and @Supplier-B" is much better than "Review everything I have open and tell me what matters." A specific request produces a more checkable answer and reveals what the user intended to share.

## Reading and comparison are the clearest wins

Comet genuinely speeds up work that begins with several sources and ends with a structured intermediate artifact. Product managers comparing competitor documentation, sales staff preparing account briefs, recruiters reviewing public role information, and founders checking vendor terms all fit that pattern. The Assistant reduces tab switching and can put facts into a consistent table before the user makes a judgment.

The word "intermediate" matters. A summary is a navigation aid, not a substitute for the source. I use it to locate the clauses, numbers, or claims that deserve direct reading. If an answer says a vendor supports regional data hosting, I ask for the exact passage and tab that supports the statement, then inspect it myself. This is faster than reading every page linearly and safer than trusting a smooth paragraph.

The poor use case is a broad request with no output contract. "Research this company" invites an arbitrary collection of facts. A better request defines the decision, sources, fields, and missing data policy:

```text
Using only @Pricing, @Security, @Terms, and @Support:
build a table with contract minimum, cancellation notice,
SSO availability, audit-log availability, support hours,
and data-retention controls.
For each cell, give the source tab and a short supporting passage.
Write "not found" when the source does not state an answer.
Do not infer plan availability.
```

That prompt creates an artifact a colleague can audit. It also blocks a common model failure: filling a blank with a plausible feature from another plan or vendor. The time saving comes from extraction and normalization. The purchasing judgment still belongs to the person accountable for it.

## Repetitive browser work improves when the boundaries are explicit

Comet can click, type, submit, autofill, and move through multistep website flows under supervision. This helps with repetitive, reversible tasks such as grouping stale tabs, collecting public details into a draft, entering the same approved text in several low risk forms, or preparing an email without sending it. The user remains in the interface where the work happens and can correct the path.

The popular recommendation is to hand the Assistant a complete routine and measure how many clicks disappear. That is wrong for a first pilot. Long routines combine reading, judgment, and side effects, so a failure near the end can undo the earlier time saving. Split the routine at the point where authority changes.

For example, consider a weekly partner update. The safe automation reads approved source pages, extracts changes, and drafts the update. A person checks names, numbers, confidential details, and recipients. Only then does the browser place the approved copy into the sending tool. Sending stays a separate confirmation. If the draft is wrong, nothing outside the browser has changed.

Use four labels when reviewing candidate workflows:

- Read: the Assistant observes information but changes nothing.
- Draft: it creates content that is not yet published or sent.
- Prepare: it fills a form or composes an action for review.
- Commit: it sends, purchases, deletes, publishes, grants access, or changes a system.

Comet is easy to approve for Read and often useful for Draft. Prepare needs a visible review state. Commit should remain narrow, confirmed, and unavailable on sensitive domains unless the business has tested the exact action. This classification is more useful than calling a workflow "agentic," because it tells an administrator what can go wrong.

## Email and calendar access trades switching for exposure

Email and calendar workflows can save real time, but they place the Assistant next to some of the most sensitive routine data in a company. With Gmail and Google Calendar connected, official Comet guidance says the Assistant can summarize threads, draft or send replies, find schedule conflicts, schedule or reschedule meetings, and prepare a briefing for the day. Those functions remove searching and context switching for people with crowded inboxes.

The first approved use should be retrieval, not sending. Asking for unresolved conversations with a named supplier, followed by links back to the relevant threads, has a clear verification path. Asking the Assistant to reply to every message that looks overdue gives it too much discretion over tone, commitments, and recipients.

A failure I have seen in adjacent automation work follows a predictable chain. A message contains an old price, the latest correction sits deeper in the thread, and the generated reply repeats the old figure. The draft sounds professional, so a rushed manager sends it. The automation saved two minutes and created a commercial dispute. The remedy is not a longer generic prompt. Require the draft to list every number, date, promise, and recipient it used, then compare those items with the source thread before sending.

Calendar actions need the same care. Reading availability and proposing options is low risk. Moving a customer meeting can trigger travel changes, missed attendees, or a broken commitment. Keep external rescheduling at Prepare until a person checks time zones, attendee scope, conferencing details, and the message that guests will receive.

I would also separate browser profiles. A pilot profile should contain the minimum accounts and extensions needed for the approved workflow. Mixing personal mail, company administration, customer systems, and finance in one profile expands the consequences of a bad instruction or a mistaken tab reference.

## The privacy model has three different data paths

Comet's privacy model makes sense only when you separate local browser data, request context, and account data. Saying "the data stays local" without those qualifications is incomplete.

First, ordinary browser material such as browsing and search history, cookies, cached files, autofill form data, and download history is stored on the device by default. Saved passwords use the operating system vault. Perplexity's local storage documentation says browsing information leaves the device if the user explicitly syncs settings with a Perplexity account. That resembles the trust boundary people expect from a modern browser.

Second, Assistant work can send context to Perplexity. Summarizing a page requires page content. A query against `@tab` requires content from that tab. A personal search may use relevant history, and an email task needs email context. The Comet Assistant privacy guide says only the context required for the request is sent, rather than the full browsing history or every open tab. It also says page, history, or tab context used for Assistant requests can be retained for up to 30 days to support Library and query history, with those threads marked temporary.

Third, account settings affect training and retention. Perplexity's data collection guidance says AI data retention is enabled by default for Free, Pro, and Max users and can be turned off in account preferences. The opt out applies to later collection, and service operation, security, legal compliance, and product improvement can still require processing. Perplexity says Enterprise data is not used to train its models. A procurement review must read the terms for the plan the company will actually deploy, not assume an Enterprise statement covers a consumer account.

Incognito does not collapse these paths into one. Closing an Incognito window removes local history, cookies, site data, and form entries from that session. If the user invokes an AI feature, the query and required context still go to Perplexity for that request. Security and abuse records may also remain. Incognito is useful for local session hygiene, but it is not a promise that an Assistant request stays on the device.

Before a pilot, capture these settings and decisions:

- Whether AI data retention is enabled for each test account.
- Whether account sync is enabled and which browser data it covers.
- Which domains block the Assistant or allow read access only.
- Which connectors are active and who authorized them.
- Which actions require a human confirmation and recorded evidence.

This record should live with the pilot decision, because screenshots of a successful demo say nothing about the data path.

## An authenticated browser raises the cost of a bad instruction

An AI browser operates inside authenticated sessions, so web content can influence an Assistant that also has permission to act. A malicious or merely confusing page can contain text that looks like an instruction. Models can misread that content, select the wrong control, or carry a value from one site into another. This class of risk is often called prompt injection, but the practical issue is simpler: untrusted page content sits beside the mechanism that clicks and types for the user.

Confirmation dialogs help, but they cannot repair a user who approves without understanding the action. Perplexity says an advanced agent asks on first run whether to allow it once, always allow it, or deny it. "Always allow" is convenient and therefore dangerous on mixed purpose profiles. Keep one time approval during a pilot, especially for sites that contain customer content or administrative controls.

The Enterprise controls are materially more suitable for managed deployment. Official documentation describes support for MDM deployment on macOS and Windows, hundreds of Chromium based policies, extension and URL controls, and domain specific Assistant permissions. Administrators can disable browser control, block the Assistant on selected domains, or make a domain read only. Existing Chrome policy work can often carry over, but teams still need to test actual enforcement rather than equate policy count with safety.

I would block Assistant action on password managers, identity providers, cloud consoles, source control administration, banking, payroll, and production databases. Reading may also be inappropriate on pages containing secrets, health information, legal privilege, unreleased financials, or regulated customer data. If a workflow truly needs one of those systems, use a dedicated profile, the narrowest account role, a documented test case, and an approval owner who understands the consequence.

Extensions deserve review too. Chromium compatibility is useful because users keep familiar tools, but every extension adds code and permissions to the browser. Start a pilot with an allowlist, not a full import from a personal Chrome profile. The goal is to evaluate Comet, not an unknown combination of Assistant access and years of accumulated extensions.

## Personal search recovers context, not company knowledge

Personal search is useful when a person remembers seeing something but cannot remember where. Comet can search relevant browsing activity, videos, and documents in response to a request. For a founder who opened dozens of market reports or a product manager who compared several support pages last week, this can recover the trail without reconstructing search terms and dates by hand.

Treat the result as a personal recall aid. Browser history shows what one user visited, not which document the company approved or which record is current. It may contain a draft policy, an outdated price page, or a customer document opened for a different purpose. If the retrieved item will influence a decision, move back to the source and check its owner, status, and effective date.

Voice mode can reduce interface work in the same narrow way. Official Comet material says users can ask about visible content, move through sites, and continue a conversation while changing tabs. That is handy during a live review or when the user's hands are occupied. In an office, voice also creates an obvious confidentiality problem: prompts and spoken answers can expose customer names, personnel issues, or deal terms to everyone nearby. Headsets reduce the audience but do not change the data path.

Neither function replaces a shared knowledge system. A team needs stable document ownership, permissions, revision history, and a way to mark approved material. Comet can help find and interpret what a user can access, but the browser does not turn a visited page into an authoritative company record. If personal search repeatedly finds information that colleagues cannot locate, fix the repository and naming practice instead of making one person's browser history the index.

This also affects onboarding and offboarding. A workflow that depends on an employee's local browsing history will not transfer cleanly when that person changes roles. Write shared prompts against named repositories and source types. Use personal search for recovery, then put the recovered source in the place where the next person will expect it.

## The browser does not remove integration work

Comet can act through a website interface, which makes unsupported tools look automatable without an API project. That advantage is real for a pilot, but browser control remains sensitive to page layout, permissions, login state, consent dialogs, and product changes. A workflow that succeeds ten times can still stop when a button moves or a session expires.

Do not compare browser automation only with manual clicking. Compare it with the best stable integration available. If a system has a supported API, event log, role model, idempotency controls, and a test environment, an engineered integration may cost more at the start but behave better at volume. The browser is attractive when the task has modest frequency, the interface is the only practical access point, and a person already reviews the result.

The distinction between convenience automation and process infrastructure matters. Drafting six partner updates each Friday is a reasonable browser workflow. Changing thousands of customer records is process infrastructure. The second task needs repeatable inputs, validation, retry behavior, rate handling, audit evidence, and a safe rollback. A visible browser agent does not supply those properties merely because it can complete the first few records.

Businesses should also test the boring compatibility details. Comet is available on supported macOS and Windows environments, while a company's device fleet, endpoint security, proxy, certificate, and extension requirements may be broader. Confirm that required extensions work, managed policies arrive on the device, blocked sites remain blocked, updates install through the normal management path, and support staff can identify the browser version during an incident.

Write down the fallback for every approved workflow. If the Assistant cannot read a page, selects the wrong tab, or encounters an unfamiliar dialog, the user should stop and return to the manual method. Do not teach users to repeat a failed action with broader wording or more permission. That instinct often turns a contained failure into an unintended commit.

## Good answers still need source checks

Comet can make research faster without making generated answers authoritative. It uses page context and Perplexity search, but a well written response can still omit a condition, merge two plan levels, misunderstand a table, or rely on stale material. Citations make checking easier; they do not transfer accountability to the browser.

Use a verification rule based on consequence. A low consequence summary of an industry article may need a quick spot check. A vendor comparison should trace every decision field to a source. Legal terms, security claims, prices, dates, and customer commitments need direct review in the original page or document. If the source is a scanned PDF, a complex spreadsheet, or a dashboard whose meaning depends on filters, assume extraction can fail until the user confirms it.

Ask the Assistant to expose uncertainty instead of hiding it. Useful instructions include "separate stated facts from your inference," "quote the supporting passage," "name the source tab for each row," and "mark conflicts without resolving them." The resulting answer may look less polished, but it is easier to trust because gaps stay visible.

There is also a freshness problem. A browser can retrieve a live page, while a search result or open tab may hold older information. Include the effective date or page update date in the requested output when the decision depends on time. For recurring research, compare the new source with the previously approved artifact rather than asking for an ungrounded summary each week.

The right metric is verified time saved. If an analyst saves 20 minutes on reading but spends 25 minutes repairing unsupported claims, the workflow failed. Measure extraction time, review time, correction count, and consequential errors separately. A single "hours saved" estimate hides the part that determines whether the result can enter a business process.

## A business pilot should test workflows, not enthusiasm

A useful Comet pilot takes a small group of real users, a few bounded workflows, and two weeks of observed work. Do not begin by making it the default browser for the whole company. Browser history, extensions, logged in accounts, and individual approval habits make a broad rollout hard to reverse cleanly.

Choose workflows with enough repetition to measure and a low cost of failure. Good candidates include comparing vendor documentation, briefing a meeting from approved public and internal sources, summarizing a long support thread into a draft, and preparing updates in a nonproduction tool. Exclude financial transfers, access changes, bulk deletion, production administration, and unsupervised external messages.

For each workflow, write a one page test card:

```text
Workflow: Vendor security comparison
Allowed sources: Named public vendor tabs and approved PDFs
Assistant authority: Read and Draft
Forbidden data: Customer records, credentials, private contracts
Required output: Table, source tab, supporting passage, missing fields
Human check: Security owner verifies every decision field
Success: Lower total research time with no unsupported decision fields
Stop condition: Sensitive data is sent, a source is invented, or a site changes
```

Run the old method and the Comet method on comparable tasks. Record total elapsed time, hands on time, review time, corrections, and actions the user had to undo. Interviewing users matters, but browser novelty produces generous opinions during the first days. Work samples and error logs tell you whether the advantage lasts.

At the end, approve each workflow separately. One team may allow research across public tabs, permit email drafting for a limited group, and ban browser control on administrative domains. That is a coherent result. "Comet approved" is too broad to be a useful governance decision.

## Comet is worth adopting selectively

Comet is worth using when browser context is the bottleneck and the output remains easy to inspect. Cross tab comparison, source guided summaries, retrieval from browsing activity, tab organization, meeting preparation, and draft creation can remove tedious motion without asking the Assistant to make the final decision. Chromium compatibility also lowers the cost of a controlled trial.

The case weakens as authority and sensitivity rise. Sending messages, editing records, submitting forms, and rescheduling meetings can still be worthwhile, but each needs an explicit review point. Work involving credentials, money, production access, regulated data, or binding commitments should stay outside general Assistant control unless an Enterprise deployment supplies the needed restrictions and the company has tested them.

For a founder, the staffing question is not whether an AI browser can imitate a junior operator for a polished demonstration. The useful question is which minutes it removes from a repeated workflow after verification and governance are counted. That is also how I approach a Team & AI Audit: map the work, separate judgment from browser motion, measure the full loop, and automate only the part that stays cheaper after review.

My practical recommendation is to install Comet for a small research heavy group, disable or restrict Assistant access on sensitive domains, keep one time action approvals, and test three workflows with written source and review rules. Promote the workflows that save verified time. Leave the rest in an ordinary browser until the controls or the task design improve.
