Android 17 QPR2 Beta 4 changes how sideloading works. Instead of sending you into Settings to hand a browser or file manager blanket permission to install apps, the beta puts a dialog in front of you at the moment of installation — and lets you grant that permission for one install only, after which it is revoked automatically. It is one of three additions that have surfaced in Beta 4 since release, and all three sit in the same place: the part of Android that decides what software and what services get to reach your data.

The Android 17 sideloading permission is now a one-time grant
Until now, installing an APK from outside an app store meant granting the app you downloaded it with — Chrome, Files, a third-party file manager — the “Install unknown apps” permission. That is a standing permission. Grant it once to install one APK and the app keeps it indefinitely, free to trigger further installs later without asking again. Most people never go back and turn it off, which is exactly the state a malicious or compromised app wants your phone to be in.
In Beta 4, the request appears as an inline system dialog with three options: allow it only this time, always allow, or don’t allow. Picking the first option grants the permission for that single installation and drops it once the APK has finished installing. The permanent option is still there for anyone who sideloads often enough to want it, and the underlying list remains at Settings > Apps > Special app access > Install unknown apps, where each app can now be set to always allow or ask every time.
This is a real reduction in standing risk rather than a cosmetic change, and it arrives while Google is otherwise tightening the screws on installing apps from outside Play — the 24-hour waiting period for advanced sideloading started reaching phones earlier this month. A one-time grant is the version of that instinct that costs the user nothing.
An Agents page appears under Privacy controls
Beta 4 also adds an Agents entry at Settings > Security & privacy > Privacy controls. Its description says it lists agents that can access information or take actions inside apps — which is the plain-language version of what an AI agent doing your shopping, booking or form-filling actually does. On the beta builds it has been found on, the page is empty and prompts you to install an agent for anything to appear.
Empty is the point worth noting. Google is building the supervision surface before the agents themselves are widespread, and the page is expected to cover third-party agents as well as ones created through Google’s own tools, not just Gemini. That matters because the current situation is the opposite of supervised: we have already seen that Android 17’s App Lock keeps people out but not AI agents. A dashboard that can name which agents hold that reach — and, one hopes eventually, revoke it — is the missing half.
Private Compute Core gets a data logging menu
The third addition is a Data logging section for Private Compute Core, the sandbox that runs on-device machine learning features, inside the Privacy Dashboard. It offers two tiers: Limited, which records a subset of data for up to three days or 100MB, and Detailed, which captures fuller raw logs for up to 12 hours or 100MB and carries a warning that those logs may contain sensitive information. Logging can be switched off, and what has been collected can be downloaded or deleted.
Read it for what it is. This is diagnostic logging, aimed at people who want to audit what an on-device AI feature is doing, and the 12-hour Detailed tier is a debugging tool rather than something to leave running. The genuinely useful part for everyone else is the delete control.
Beta only, and undocumented so far
All three are in the Beta 4 build, which reached supported Pixels last week, and none of them is guaranteed to ship in the stable QPR2 release in the form described here. Google’s Android 17 release notes page, checked on 31 August, documents QPR2 only as far as Beta 3 and does not list any of these three changes — so for now the descriptions rest on what has been found in the build rather than on anything Google has written down.
Sources: Android Authority on the install permission, the Agents dashboard and Private Compute Core logging, Android 17 release notes







