Security and access
Understand repository scope, team access, webhook security, and data boundaries.
Fullbeam keeps access within the selected repositories and connected team workspace. Private qualification runs in isolated, ephemeral Fullbeam environments using customer-authorized repository access and customer-owned provider credentials.
Isolated Fullbeam execution · Ephemeral workspaces · Customer-owned provider credentials
Repository access
- The GitHub App can access only the repositories selected during installation.
- Fullbeam checks workspace and repository entitlements for release, task, decision, and supporting PR evidence.
- A copied report or Story link does not grant access to someone who is not entitled to the underlying repository.
- Removing a repository or uninstalling the GitHub App stops future events for that repository.
Team roles
Workspace owners manage source connections, members, Stack Releases, private-suite metadata, policies, comparisons, overrides, and recorded decisions. The coding-agent vendor, GitOps, MDM, or internal platform remains the rollout authority. Members use qualification and supporting evidence features allowed by their role.
Webhooks and runtime data
- GitHub webhook signatures are verified before events are processed.
- Fullbeam temporarily materializes private task content and repository source inside an ephemeral managed attempt. The workspace is destroyed after evidence packaging.
- Managed attempts are configured for Daytona's EU target. Release admission requires a retained live canary proving regional placement, network enforcement, opaque-secret behavior, and cleanup for the deployed release.
- Provider calls pass through the Fullbeam model gateway and require an authorized qualification attempt; the gateway is not a general prompt API.
- Provider credentials are encrypted behind the Fullbeam model gateway and excluded from reports and evidence. The sandbox receives only a short-lived attempt token, which is destroyed with the workspace.
- Hidden graders are materialized only for the separate post-agent verification phase.
- Raw local agent transcripts are not required for production outcome correlation or GitHub-only PR evidence.
- Runtime sources can be unavailable or redacted, but decision-driving coverage gaps remain explicit and can block an ordinary promotion.
- Digests bind control-plane records to frozen task assets, exact Git states, Stack Releases, and normalized evidence; GitHub and the repository remain authoritative for code changes.
Use the Security page for the current security and data-handling summary.