Security
Runtime and account boundaries
Agent commands execute inside the selected provider's environment. Account checks control access to saved configurations and machine operations, and saved keys are redacted in normal configuration responses. Provider isolation, runtime permissions, and the credentials you supply define the security boundary; a template is not a safety policy.
- scoped env
- private keys
- provider boundary
- account → access to saved configurations
- provider → remote execution boundary
- runtime → native permissions and tools
- service keys → permissions you grant
Capabilities
What you can use.
- Saved keys
- redacted
- normal configuration responses
- Machine records
- scoped
- per account
- Isolation
- provider
- inspect the selected environment
Workflow
From setup to result.
Connect
Supply keys for the provider and model you intend to use.
Limit
Review runtime permissions and use narrowly scoped service credentials.
Inspect
Read operations, command output, and available native history.