Reference 48 pages
On this page

Reference

Daemon access

Who can reach a machine that runs your agents, and what each level of access unlocks.

A machine (the Cyborg daemon running on a computer) is the agent host. It runs agents and terminals and connects them to your workspaces through the relay.

Access to a daemon is separate from membership in a workspace. Workspace membership gives you its channels, tasks and pages. It gives you nothing on anyone’s machine. Reaching a machine requires either owning its daemon or holding an explicit grant on it.

Scopes

A grant is a set of scopes, not a yes/no switch.

ScopeWhat it unlocks
chatPrompt agents that already exist on that daemon. The lowest rung
spawnLaunch agents, run slash commands, manage schedules, and change an existing agent (model, mode, thinking level, rewind, archive, restore)
terminalOpen a terminal (shell) on the host
adminEverything, including updating the host. Treat as remote code execution

terminal and admin give code execution on the host.

A grant can also read Off. That is stored as a fifth value, blocked. It is not a capability: it is an explicit “no access” for one person that wins over a workspace machine’s default role for members. It grants nothing.

Access is also separate from session access. A scope lets you talk to a machine. It never lets you read another person’s private session.

Presets

The UI offers three presets and stores the scopes behind them:

PresetScopes
Viewerchat
Operatorchat, spawn
Adminadmin

Admin is stored as the single admin scope rather than the expanded list. It is the “total access” grant and matches what the daemon’s owner already has.

Any other combination is possible and shows as Custom.

Only the owner grants

The person who enrolled the daemon owns it, and only the owner can change who reaches it. Being a workspace admin is not enough. A workspace role covers the workspace’s data, and a daemon is someone’s computer.

The owner implicitly holds every scope on their own daemon.

Someone who needs access can ask for it. The request lands in the owner’s inbox, and the owner approves it, optionally with narrower scopes than were requested. A request from the owner is refused, because there is nothing to grant.

Revoking is clearing all the scopes, which removes the grant entirely.

Workspace machines

A workspace can also own a workspace machine: a machine connected with a one-time setup code (CYB-XXXX-XXXX) instead of a personal login. On the machine, run cyborg daemon join --code CYB-XXXX-XXXX (see the CLI reference). Members can be given a default role on such a machine, and an individual Off overrides it.

Acting as an agent

An agent runs on a home machine. Anything that acts with that agent’s identity, such as minting an MCP token whose “Acts as” is the agent, requires that you hold access on that machine. Authority over an agent is authority over the machine it runs on.

Two consequences produce no error message:

  • An agent you cannot reach does not appear in the “Acts as” dropdown. This is the access check, not a bug.
  • An agent with no home machine fails closed: no token can be minted for it.