Admin workspace

Backend-mediated reads and writes only
Guarded runtime

Workspace

Guardrails

Frontend shell only
  • Direct provider API callsDisabled
  • Risky model-originated writesApproval required
  • Session exchangeBackend required