KEORISRETURN TO KEORIS

PERMISSION IS THE ARCHITECTURE

Powerful enough to act.
Bounded enough to trust.

The local assistant and developer coding jobs use different controls. Assistant actions go through KEORIS's built-in tools. Claude Code and Codex jobs can work on your projects through their own runners, with KEORIS restrictions added. A job is not a words-only chat.

ASSISTANT TOOLSBuilt-in file tools use approved folders and confirmation gates.
DEVELOPER JOBSClaude Code uses your configured rules plus KEORIS restrictions. Codex runs with an assigned project boundary.
OPERATOR CONTROLReview the job and its permissions. The Jobs panel gives you a Stop control.

Developer build: Claude Code and Codex

The developer build connects to your signed-in Claude Code and Codex installations. Public Windows access is coming soon. These are connected coding tools: their work may read files, edit code, and run commands. Your provider's account settings, availability, and usage limits still apply.

A project write boundary is not a promise that all processing is local or that a job can never read outside that folder. Claude and Codex send the context they use to their connected providers. Review the assigned project, your runner settings, and the requested work before starting.

Local assistant: files and destructive actions

Local assistant: screen vision and screen driving

These limits describe KEORIS's built-in Screen Driving feature. A permitted Claude Code computer-use or browser tool follows the coding runner's controls; it is not the same feature.

Local assistant: browser isolation

Pages in KEORIS's built-in assistant browser run in isolated sessions without access to KEORIS files, settings, keys, or internal controls. Camera, microphone, and location requests are denied by default. Downloads are disabled in that browser stage, and local-file URLs are refused. This does not describe a coding agent's separate browser tools or the separate KEORIS Desktop app.

Cameras and remote access

Known limitations

The public Windows installer is still being prepared and may be unsigned. Windows secure storage protects keys when available, but some non-OpenAI connected-service secrets can fall back to plain text in the local settings file. Local records are not all encrypted. Connected Claude and Codex workflows necessarily send the context they use to their providers.

These controls reduce the scope of a job; they do not guarantee that generated code or commands are correct. Changes made through a permitted runner still need review. This page describes the developer build and the assistant features identified above, not a completed public-release security audit.

See the full Privacy page for network destinations and local-storage behavior.