Watch only reads. You decide what changes.
An agent reads text an attacker may have written. So Ingot treats it as the least trusted part, and enforces the controls outside it.
What an agent can do
- Read logs, metrics and cloud state through nine read roles.
- Read the repos you name, with GET requests only.
- Run read-only queries on a database you name, with a row limit.
- Commit a fix to a branch and open a pull request.
What it cannot do
- Write to your cloud.
- Push to your default branch or merge a pull request. You merge, or your rules do.
- Hold a key that merges or deploys. Ingot’s console holds them and applies your rules.
- Close the ticket for its own fix. Watch does, once the problem is resolved.
- See an API key, your GitHub token or a database password.
- Post to Slack or send an email. The console sends every message.
- Read another customer’s data. Each has its own runner and cloud identity.
Nine read roles to watch.
Each customer gets its own runner and service account. Ingot never asks for roles/viewer. Auto-deploy adds deploy roles, held by the console, and only if you enable it.
roles/logging.viewer roles/monitoring.viewer roles/cloudasset.viewer roles/serviceusage.serviceUsageConsumer roles/compute.viewer roles/run.viewer roles/container.viewer roles/dns.reader roles/certificatemanager.viewer
Your keys stay out of the agent’s reach.
A proxy holds the keys
The agent runs with a placeholder key. A supervisor injects the real one into each request.
Model usage is included
Ingot pays for it and selects the model. Your own API key on request.
Retained for 30 days
Run records, evidence and transcripts, unless you change that.
The agent’s word is not final
Plain checks run first. A finding without evidence is discarded.
Sign-in
Passkeys first. Invites expire after 24 hours.
Your own machine
The Local Runner makes outbound connections only, on networks you choose.
Report a problem
Found a security problem in Ingot? Tell us first, with the steps to reproduce it.
Write to security@ingot.run.