rye.ai

Rye supervision workbench

Workspaces

Use Rye workspaces to centralize users, devices, policy, and audit records for an engineering organization.

route
/docs/auth/workspaces
control point
external supervisor
signals
proxy / policy / audit
01Claude / Codex
02Rye local proxy
03policy + audit
04model API

Workspace model

A workspace is the boundary for policy, devices, members, and audit records. Developers authenticate into a workspace, then their supervised agent sessions are evaluated against that workspace's active policy.

Members

Workspace members are users who can authenticate devices, view permitted audit data, and administer settings according to their role.

Devices

Devices represent local machines that are allowed to run supervised traffic. Device records help with incident response because they connect a prompt or policy decision to a physical workstation.

Policy inheritance

Workspace policy should be treated as the organizational source of truth. Local prompt files such as CLAUDE.md or AGENTS.md are useful guidance, but they are not enforcement. Rye policy is applied outside the agent runtime.

Operational guidance

Keep workspace membership tight. Revoke devices when people leave or machines are replaced. Review device inventory during security reviews and incident response.