Rye supervision workbench
Workspaces
Use Rye workspaces to centralize users, devices, policy, and audit records for an engineering organization.
Workspace model
A workspace is the boundary for policy, devices, members, and audit records. Developers authenticate into a workspace, then their supervised agent sessions are evaluated against that workspace's active policy.
Members
Workspace members are users who can authenticate devices, view permitted audit data, and administer settings according to their role.
Devices
Devices represent local machines that are allowed to run supervised traffic. Device records help with incident response because they connect a prompt or policy decision to a physical workstation.
Policy inheritance
Workspace policy should be treated as the organizational source of truth. Local prompt files such as CLAUDE.md or AGENTS.md are useful guidance, but they are not enforcement. Rye policy is applied outside the agent runtime.
Operational guidance
Keep workspace membership tight. Revoke devices when people leave or machines are replaced. Review device inventory during security reviews and incident response.