An agent that can use your app needs boundaries it cannot cross.

Nine controls, in the order a run meets them. Then the two things we would want to know before trusting it ourselves.

LayerControlWhat it means in practice
BrowserPer-job isolationEach job gets its own browser context. Cookies, storage and sessions never survive a job, even when several jobs share one browser process.
EnvironmentsPrivate by networkApps under test run in per-job namespaces with default-deny networking and mutual TLS on the worker-to-app hop. Only the assigned worker can reach a box.
CodeA git host the agent cannot escapeAgent edits push only to a platform-owned host; pushes to any other remote are refused. Your repository changes only when a person graduates a change.
CredentialsWrite-only, vault-storedRepository tokens and model keys are set once, stored in the vault and never re-exposed through the API or dashboard. Env-local secrets win over a shared base tier.
APIScoped, revocable keysArea-scoped keys with read and write halves, shown once, hashed at rest, greppable by prefix. Access is scoped to the project, not the caller.
AgentsPer-job credentialsCode-change jobs receive credentials minted with only their task's scopes, revoked at terminal state. What an agent may do in a run is granted by tag, as data.
IdentityFederated, no stored secretThe platform's cloud identity is workload-federated. Dashboard access is through your organisation's identity provider; the public site holds no user data.
PagesStrict content policyDashboard and site ship a content security policy with no inline scripts and no third-party hosts, as a header and a meta tag.
DecisionsPeople at every gateThe agent never merges, never closes an issue, never publishes a release, never writes to your repository on its own. Authored tests land disabled; proposed changes wait for review.

Two honest gaps.

Access control inside the dashboard. Every signed-in user sees every project. For an internal platform that is a convenience; before an outside organisation is given a login it is a blocker, and it is not built yet.

MCP credentials. An external agent calling the platform as an MCP server uses the same API keys as REST. Scope the key narrowly; there is no MCP-specific credential model.

Everything the agent posts states that AI-generated content may be incorrect.

The Settings view: API keys with scopes, shown once when minted, with revocation; write-only model keys; GitHub App identity per owner.