How it works
Propose → gate → Linux host
AI diagnoses and drafts commands. The app on your machine holds the keys, asks for approval, then SSHs. Cloud keeps metadata, not keys.
From installing the app to a command running on the server
- Install Desktop, SSH immediately
Local Mode needs no account. Import PuTTY/WinSCP sessions or create a host profile, attach secrets in Vault, Connect.
- Describe the incident — the agent investigates
Three fixed steps: clarify the goal, read evidence on the server, then propose changing commands. You see each command and its output.
- Approve on your machine
Desktop is the last gate. The backend does not open SSH to the client. Changing commands usually wait for you.
- Sign in when you need a team
Metadata sync, Access, cloud audit, and Protected/Team workspaces. Secrets stay in the local vault.
Propose → gate → Linux host
- auto_awesome
AI proposes
The model diagnoses and drafts commands. It does not execute, and it does not open SSH to your machine.
- arrow_forward
verified_useryou approve
Desktop is the last gate
The app on your computer holds the keys, asks for approval on changing commands, then runs them.
- arrow_forwarddns
Your Linux host
The SSH session goes straight from Desktop to the server. Logs stay on your machine.
You can read what the agent is thinking, doing, and citing
Every AI Ops session is an open timeline: each read command, the output, the conclusion, and why a fix is proposed. No black box — you approve because you see evidence, not because you trust the model.
Evidence travels with the conclusion
Every diagnosis points at the command and output that produced it. Click through to the original text.
Cost and time per step
Credits, command count, duration per step — know what the agent costs before you turn it on for the team.
Reports stay on the machine
The whole session is a readable local log — incident review without the cloud.
This is not web SSH
The backend does not open SSH to the client and does not store secrets. The web has an API but it does not replace Desktop for running commands — to run anything, the app on your machine must be open.
Read 5 security promisesarrow_forwardDownload Desktop and SSH now
Local Mode runs with no account: import existing SSH sessions, open a terminal, use the vault and recorder. Sign in only when you need metadata sync, access, or cloud audit.
No, not to SSH. Access, cloud audit and sync need a sign-in.
No. Sync pushes profile metadata; secrets stay in the vault on your machine.
A workspace type stricter than My: sensitive actions need a grant or approval.