PERMISSION IS THE ARCHITECTURE
Powerful enough to act.
Bounded enough to trust.
The local assistant and developer coding jobs use different controls. Assistant actions go through KEORIS's built-in tools. Claude Code and Codex jobs can work on your projects through their own runners, with KEORIS restrictions added. A job is not a words-only chat.
Developer build: Claude Code and Codex
The developer build connects to your signed-in Claude Code and Codex installations. Public Windows access is coming soon. These are connected coding tools: their work may read files, edit code, and run commands. Your provider's account settings, availability, and usage limits still apply.
- Claude jobs start in the selected project with your existing Claude setup. KEORIS adds blocked tools and applies your configured ask and deny rules, including corresponding Bash and PowerShell rules.
- Codex jobs require a project and use a restricted runtime that confines writes to that project folder. They cannot request permission to leave that boundary. Codex does not inherit every plugin or permission from your normal desktop session.
- KEORIS blocks trading, fax, and messaging tools for jobs and adds rules against changing the settings that control the run.
- Starting a job authorizes work under its rules. It does not mean every file change will pause for a fresh click, or that the assistant's Recycle Bin behavior covers coding-agent commands.
- Stop ends the running job; it does not undo changes the job has already completed.
A project write boundary is not a promise that all processing is local or that a job can never read outside that folder. Claude and Codex send the context they use to their connected providers. Review the assigned project, your runner settings, and the requested work before starting.
Local assistant: files and destructive actions
- Search and document tools enforce approved-folder boundaries outside the interface.
- Moves, renames, and deletions require confirmation.
- Deletes use the Windows Recycle Bin. KEORIS refuses deletion when a network drive, oversized file, or unavailable Recycle Bin could cause permanent erasure.
- Backups exclude stored secrets.
Local assistant: screen vision and screen driving
- Screen vision always displays a visible indicator while an image is being read.
- Screen Driving is beta, off by default, and currently limited to File Explorer and Notepad.
- You see and approve a plan first. Save, send, delete, download, and overwrite steps pause again.
- Financial windows, sign-in surfaces, password fields, administrator windows, and UAC prompts are blocked.
- Screen driving cannot run unattended, from a schedule, or from the phone companion.
These limits describe KEORIS's built-in Screen Driving feature. A permitted Claude Code computer-use or browser tool follows the coding runner's controls; it is not the same feature.
Local assistant: browser isolation
Pages in KEORIS's built-in assistant browser run in isolated sessions without access to KEORIS files, settings, keys, or internal controls. Camera, microphone, and location requests are denied by default. Downloads are disabled in that browser stage, and local-file URLs are refused. This does not describe a coding agent's separate browser tools or the separate KEORIS Desktop app.
Cameras and remote access
- Local RTSP camera helpers bind to the loopback address rather than the open network.
- Blink live-view sessions use short-lived, unguessable local tokens and are released when viewing stops.
- Cloud camera traffic uses the camera provider because that is how Ring, Blink, and Nest operate.
- The mobile companion binds to Tailscale and refuses to fall back to an exposed local-network server.
Known limitations
The public Windows installer is still being prepared and may be unsigned. Windows secure storage protects keys when available, but some non-OpenAI connected-service secrets can fall back to plain text in the local settings file. Local records are not all encrypted. Connected Claude and Codex workflows necessarily send the context they use to their providers.
These controls reduce the scope of a job; they do not guarantee that generated code or commands are correct. Changes made through a permitted runner still need review. This page describes the developer build and the assistant features identified above, not a completed public-release security audit.
See the full Privacy page for network destinations and local-storage behavior.