- An agent receives the task, user updates, its role, and its own private work product.
- Peer agents receive neither another agent's
analysis.mdnor its clarification workspace. - The chair receives public briefs and targeted clarification answers, not private analyses.
- During peer review, each reviewer receives the chair draft plus its own private analysis and brief.
- Private notes are still available to the local user and are included in the local audit record. “Private” means private from other model calls, not encrypted from the machine owner.
Workspace directories use 0700; files use 0600. The session directory and the
audit directory (~/.local/share/x-sidechain/sessions) are also 0700, and audit
logs are created 0600: they contain the task text and every model reply, so they
must not inherit a world-readable umask. Agent IDs are validated before
being used as path components, and relative workspace writes reject .. and absolute
paths. This is not yet an OS sandbox: agents currently have no tools and cannot access
the filesystem directly. Future tools must be confined to the owning agent directory.
- API keys come from environment variables named in configuration.
- A provider
base_url(or OAuth endpoint) on cleartexthttp://is rejected unless the host is loopback, because the API key and the task would cross the network in the clear. Set"allow_insecure_http": trueon that provider to accept the risk deliberately, for example for a trusted host on a private link. - Keys and OAuth tokens are excluded from configuration output, workspaces, and audit payloads. A provider that echoes the request could return the very credential used to call it, so an error body is scrubbed of the outgoing auth header values, and of common token shapes, before anything is written to disk.
- OAuth is allowed only through provider-published Device Authorization Grant values.
- OAuth tokens are stored through Linux Secret Service using
secret-tool. - ChatGPT account credentials are owned by the official Codex CLI. X-SIDECHAIN
calls
codex loginandcodex login status; it never reads or copies the Codex credential file. - Every Codex child receives an explicit allowlisted environment containing only
process, account-store, locale, certificate, proxy, and desktop-login necessities.
Provider API keys—including
OPENAI_API_KEY—and arbitrary configured secret variables are never inherited by Codex. This also prevents an account-backed provider from silently switching to API-key billing because of the parent process. - Account-backed model calls use an empty temporary working directory, ephemeral sessions, read-only sandboxing, ignored user configuration and execution rules, and disabled shell, search, image, memory, skill, and multi-agent tools. Only the final text reply is accepted, and the temporary directory is removed after the call.
- X-SIDECHAIN never automates passwords, scrapes login pages, or reads email.
The task and user updates go to every provider selected by an agent. Public briefs, clarifications, draft, and reviews are routed according to the chaired protocol. Do not combine providers that are not all authorized to receive the task material.
- Audit chaining detects later modification but does not prove authorship or provide an external timestamp. Reopening an existing log continues its chain; a log that already fails verification is never extended.
- Superseded revision work remains in local workspaces and audit logs.
- An abstaining agent contributes no evidence. The chair is instructed never to read an absence as agreement, and every abstention is recorded with its cause.
- A provider's own error text never reaches another agent. Room events, prompts and
the audit carry only a cause this project wrote itself, such as
provider returned HTTP 503; the response body can echo request headers or another tenant's data, and the briefs of agents from different vendors share one room. The full text is written to the failing agent's private workspace asprovider-errors.log(0600) for the local operator only. That file holds text the provider chose to return, scrubbed of credentials but not otherwise filtered: it is the one place provider error content is kept, it never reaches a model, and it is readable by the machine owner like every other workspace file. - Abstentions name the step that is missing (
no brief,no clarification,no review), so an agent that filed a brief and then missed one step is never reported to the chair as absent. - Model output is untrusted text and is never executed.
max_model_callsprevents the application from starting calls beyond the session budget; calls already accepted by a provider may still be billed. Transport retries (429 and 5xx) do not consume budget but may be billed by the provider.- Aggregated provider-reported token usage is written to
session.completedand printed with the run summary. - HTTPS uses Python's default certificate validation.