Security and isolation
How Teams, Computers, Apps, and connected credentials are separated.
Fungi separates Team authority from the places that run code. These boundaries reduce what an Agent, App, or Computer can reach; they do not make code you run automatically safe. Review an App’s permissions and the access you give a Computer before using either with sensitive work.
Teams and guest code
Section titled “Teams and guest code”Your Team owns its membership, resources, and grants. A grant is permission for one operation, not a copy of a Team-wide credential. The Hub checks Team authority before dispatching guest code. Hosted guest execution runs in a Team-assigned shard with its own process user and network namespace. Shards share the host kernel: this is not a separate physical machine or a guarantee against every kernel vulnerability.
Guest code calls Team resources through a broker, which checks the invocation, grant, Team, and current revocation state. A refused or unavailable operation fails rather than falling back to execution in the Hub process. Disconnecting a resource or removing a grant stops new calls; a call already admitted may finish. If you suspect a grant is too broad, revoke it and review the affected resource’s activity.
Computers and Apps
Section titled “Computers and Apps”A hosted Computer runs in a jailed microVM: a small virtual machine with its own guest kernel. Its lifecycle, files, and processes belong to that Computer. A local folder attached through the Fungi CLI is different: commands on your machine run with your operating-system user’s access, not inside the hosted microVM. See Attach a local folder before allowing an Agent to use one.
An App has a Team-scoped installation and a published Release. Its browser surface uses an App origin and an iframe boundary; browser framing is not the authority for backend operations. The Hub checks the Team and App grant before an App backend runs in the execution shard. Do not treat another Team’s App or its data as accessible merely because you know an App identifier.
Network and credentials
Section titled “Network and credentials”Computer internet access is on by default and can be turned off in that Computer’s settings. Public requests go through a policy gateway with method, destination, and rate-limit checks; the gateway does not add your connected credentials to anonymous downloads. This is not unrestricted internet access. A private GitHub repository uses the separate Team-authorized connection path, and GitHub applies its own repository and branch permissions. See Connect GitHub for disconnect and push limits.
Provider tokens and personal model keys stay with their credential custodian, not in Team directory records or guest responses. A connected integration can be unavailable, out of scope, or revoked. Reconnect it or choose another authorized resource; do not put a provider key into an Agent prompt or App source to work around a refusal. Your own model key explains the difference between a personal key and a Team-paid request.
What these checks establish
Section titled “What these checks establish”The repository has separate native tests and scratch-host drills for shard placement, cross-Team broker refusals, App execution, revocation, and some network denials. A passing control for one path does not prove all guest-code kinds, DNS-rebinding resistance, every provider, or every deployment. Hosted microVM isolation also depends on the configured host and its operating-system permissions. Operators with access to the host and its protected stores have different authority from Team members; Fungi does not claim to hide Team data from those operators. Report unexpected cross-Team access rather than relying on these boundaries as a substitute for backups or access review.