Skip to content

Govern agent work: claims, scoped access and the audit trail

Agents work through claims (one worker per task), authenticate with scoped credentials that never exceed the permissions of whoever invoked them, write as attributed users, and leave an append-only audit trail.

Updated

One worker per task

When an agent starts a task with start_work it takes a claim. If another worker already holds a live claim, the answer is already_claimed along with who holds it and since when. Taking over is an explicit act, not an accident.

Claims are kept alive by heartbeats. If a worker dies, the claim goes stale and is reclaimed, so stuck tickets free themselves.

Scoped credentials, not a person’s session

An agent authenticates with an organization API key, an MCP OAuth token, or a token scoped to the single task it claimed. The tools it can reach are capped by the permissions of the identity that invoked it. Each tool requires a scope such as tasks:read or comments:write.

OAuth connections act as the signed-in person and only see the spaces that person selected. Organization keys are stored as hashes and expire a year after issue.

Attributed writes

Comments, status changes and edits resolve to a real actor: the person for an OAuth connection, or the creator of the key for a REST write with an organization key. A write that cannot be attributed to a real user is refused.

Deciding when agents run

Agent execution is configured per project. Dispatch is off until someone turns it on explicitly: attaching a reusable agent profile to a project never enables it, and choosing a local checkout never authorizes a remote push. The autonomy setting is one of suggest, approve or auto, and a project can be limited to opt-in dispatch so only tasks someone marks ready are picked up.

Execution runs on machines you connect, using your own repository access, so source and working files stay in your environment.

Launch, steer and stop

A launch runs a snapshot of the task text taken when you pressed Launch, so a later edit cannot change what runs on your machine. If someone edits a task while an agent is working on it, the edit is saved but they are warned that it will not reach the agent, and offered Pause and steer instead.

Stopping is a kill: cancel_run, or Stop on the board, closes the claim and parks the task so no machine immediately re-claims it. When an agent needs a decision it can use ask_human, which posts a question on the task, parks its claim as blocked awaiting input, and notifies the task owner.

What is recorded, and what is not yet

Writes through the web app, desktop, MCP and organization API keys land on an append-only audit trail; a database trigger refuses updates and deletes. Each run keeps its outcome, machine, branch, pull request and log tail.

Not shipped yet: a first-class per-action record for agent runs and an organization-wide policy engine are in development. An administrator can already halt agent work for the whole organization or one space through the admin API; there is no in-app control for it yet. SAML or OIDC single sign-on is not available. The trust page lists each control and its state.