8staff

Security

The staff lives on this machine.

Your logins, your desks, your notebook. The models you already pay for see what they would see if you ran their CLI yourself.

No proxy

Each CLI runs as itself

Claude, Codex, Grok, Cursor — OAuth as the vendor built it. No borrowed tokens, no base-URL tricks, no second pair of eyes from 8staff.

This machine

Roster, files, notebook

The floor is local-first. Desks are home folders on this Mac, PC, or Linux box. Closing 8staff ends the local shift. Open at login starts it again. Cloud desks are a separate, paid floor you turn on.

Localhost only

The engine does not serve the room

The desktop engine binds to 127.0.0.1. It is not a staff you share on a public URL.

Learning, optional

A notebook, not a cloud brain

Consent-gated, stored here, briefed versus control on your own work. Off means off. This is not overnight model training.

One check

Updates from GitHub

An optional, anonymous look at GitHub Releases, about once a day, switchable off. Installing is always your click.

Allow is yours

Sends wait in the thread

Work chips show what a teammate is doing. Mail, posts, and anything you would want to see stop at Allow or Deny.

Honest limits

  • Schedules on this machine run while 8staff is open. Cloud desks are the paid way to keep a shift after the laptop sleeps.
  • A vendor CLI still follows that vendor’s agreement — the one you already accepted.
  • Full access on a desk is an explicit choice, not a claim of OS isolation against malware already on the user account.

Privacy · Terms

Staff the night shift.