Most agent harnesses now offer some form of persistent browser profile. The tradeoff is well understood in the abstract and poorly understood in practice: a profile that carries live authentication makes the agent useful and makes every page it reads a potential instruction source.
Three broad modes have converged across implementations: a fresh throwaway profile per session, a named profile that persists between sessions, and attachment to the operator's existing browser. The third is the one that carries authentication.
The reference notes below collect the published guidance on profile attachment, including the vendor documentation and the current consensus on isolation boundaries.
Reference notes: profile attachment and isolation boundaries