Workspace isolation & access
Approve access per Workspace, restrict supported provider resources and keep control of client connections.
What a Workspace controls
Each Workspace has its own configured service grants and approved context. Brokered requests are evaluated for the registered Workspace; changing a client name in a prompt does not grant access to another client. Provider account and resource restrictions apply where supported and configured.
A credential can be shared across multiple Workspaces. Each needs its own grant, but a broad shared provider credential is not equivalent to separate provider accounts or separate machines. Where a connector has no resource restriction, a shared credential can reach whatever the provider permits it to access. Use a separate credential per client in that case.
Can a compromised agent or operator reach another client?
Workspace controls restrict requests made through Outloop. They are not an operating-system sandbox and do not protect against every action an agent can perform outside Outloop.
An agent or operator with sufficiently broad access to the Mac, files or browser sessions may cross the intended client boundary. A compromised Mac or broadly privileged operator is outside the protection provided by Workspace grants alone.
Managed Browser tabs are separated by task, but website sign-in sessions are shared across Workspaces on the same Mac. A Browser Login grant does not create a separate client session. For separate browser profiles, disable Managed Browser for that Workspace and configure a dedicated Local Chrome profile. This still does not provide OS-level isolation; assess separate OS accounts or machines with your security team.
Permissions and approvals
Operators grant service access and provider permissions during setup. Approved capabilities can allow writes, sends and other consequential actions without a new human approval for every request. Specific destructive and data-privacy capabilities have additional configuration controls; do not assume all sensitive actions pause for review.
Use the least access your workflow needs. Review provider scopes, resource restrictions and any broader host or browser access separately. Prompt instructions are not a substitute for enforced permissions.
Audit and redaction
Outloop records local access decisions and selected activity metadata. Redaction targets known secrets and sensitive patterns; it does not make every business record safe to share. The local audit is not advertised as an immutable, tamper-proof or complete record of all activity on the Mac.
Implementation engineer access
Outloop has no built-in staff remote-access path to your Mac, local credentials, policy or audit. An implementation engineer’s separately arranged access depends on what your organization authorizes: for example, a supervised screen-sharing session, local operator access, or a separately granted provider account. Broad Mac access can expose local files and other client environments.
Before an engagement, agree in writing on the people, systems, permitted work, duration and revocation steps. Do not assume a dedicated Outloop support role, automatic expiry or fully audited remote-support sessions. Ask support@outloop.co to document the proposed access arrangement.
Revocation and offboarding
- Remove the relevant Workspace grants and review shared connections.
- Revoke provider tokens, user access and browser sessions where appropriate.
- Remove remote-support and local OS access separately.
- Review local credentials, files, exports, logs and backups for deletion.
Removing a grant does not erase its Keychain credential or undo provider actions. Grant revocation stops in-flight brokered API work; a browser action already running may finish before the next action is denied. Removing a Browser Login grant does not sign the browser out. Confirm revocation on each system rather than treating one toggle as complete offboarding.