CodeHerderSearch⌘KRequest access →

Administrator briefing: visibility and trust

What every workspace member can read, what a group passes to child workspaces, and what each execution mode trusts. Your administrator signs it.

Read this page before live work starts. Your administrator signs the acknowledgement at the end.

What a member can see

Every member of a workspace reads all of its content. A role changes what a member can change. It does not change what they can read. A team is not a boundary. To restrict a project, put it in its own workspace. The full rules are in Who can see what.

What a group passes down

A role on a group reaches every workspace beneath it. Group resources inherit to each child workspace. These are agents, repositories, devices, wiki pages, workflows, integrations and variables. See Workspaces.

A device that serves several workspaces shares some components between them. See What a shared device shares.

What each execution mode trusts

Your install runs two modes.

Mode Where it runs What it trusts
process Laptops only. Your organization must accept this risk in writing. The agent runs as the device user. It reads everything that user can read. Sessions and workspaces on the device share that user.
docker (ch device-server --docker), the trusted mode Laptops and EC2. CH_TRUSTED_EXECUTION=1 is the operator’s consent. Without it, the device refuses to start. The container keeps host files away from a well-behaved agent. It does not stop a hostile or prompt-injected agent, because the container is privileged and the agent has sudo. Sessions and workspaces on one device share one container.

Use neither mode to separate two workspaces that must not see each other. Give each such workspace its own device. For agents you do not trust, run the device with --docker-executor. It puts each stage in its own unprivileged container. See Isolating agent runs on a device.

For more, see What an agent can reach on the device and Who can run code on your device.

Acknowledgement

The administrator signs this line:

I have read this briefing. I understand that every workspace member reads all workspace content, that group resources and roles pass to child workspaces, and what each execution mode trusts.

Name Date Signature

Record the signed acknowledgement in the Launch acceptance record.

Last updated

CodeHerder

Round up your herd.

Bring every human and every agent onto one table. Watch the work move. Costs update as it happens.

Try "pricing", "connect a device", or "who reviews the code"

↑↓ move · ↵ open · esc close