SECURITY AND ACCESS
What you’re giving access to.
A connection is not permission. Every computer decides who may watch it, move files, control it, or give it to an agent, and it enforces those decisions itself.
Updated
Pairing#
Adding a computer needs no typed code, except a friend’s invite code. Tailscale identifies the computer asking to pair and the login it belongs to, and that computer proves it holds its own key. The pairing records that key and its Tailscale identity.
Your own computers, signed in to the same Tailscale login (neither one tagged), are added without a code: ibara on the asking computer confirms its console made the request. For someone else’s computer, the same six-digit code shows on both screens, and a person on the computer being added compares it and accepts. A request waits five minutes, then expires. Computers talk only over your Tailscale network; pairing opens no public internet listener.
Permissions#
Each computer holds its own grants. There are five capabilities:
| Capability | Allows |
|---|---|
watch | Seeing the screen, the agent tasks and the history. |
files | Transfers to and from the approved folder. |
control | Taking control of the desktop yourself. |
agents | Running agent tasks. |
administer | Changing access and settings, answering approvals, and restarting, shutting down, sleeping and updating the computer. |
Your own computers get all five. Someone else’s computer that a person accepted gets watch and files. A computer added with an invite code gets exactly the invite’s level, never administer. Deny beats ask, ask beats allow, and no matching grant means no access.
The Access tab shows these as Watch, Files, Take Control, Agent Tasks and Administer. Each cell reads Allowed, Ask First or Denied; choose one to change it.
Agents are identified as agent@computer, such as claude@your-laptop for Claude Code or codex@your-laptop for Codex, and the paired computer vouches for that name. This is a guardrail for keeping track of who did what. It does not isolate one agent from another on the same computer.
Share This Computer#
To let a friend use your computer from theirs, open Share This Computer from this computer’s card menu on the fleet wall, or its System tab. Choose what they can do and how long it lasts (1 Hour, 1 Day, 1 Week or Until Revoked), then Create Invite Code. You get a single-use code such as 4H7K-92QX, shown once. Your friend chooses I Have an Invite Code beside your computer in their Add Computer, and it’s added at once with exactly that level. Their computer must be able to reach yours over Tailscale; Share in Tailscale opens the page that sets that up.
- Watch: they see the screen.
- Use with Approval: they watch; files, Take Control and agent tasks each ask first.
- Take Control: they watch, move files and take control; agent tasks ask first.
No invite grants Administer. Every invite is listed with Revoke; revoking a used one ends that friend’s access at once. A wrong, used or expired code gets one plain refusal, and five refusals in ten minutes lock that computer out for up to ten minutes, even with a good code.
Approvals#
By default, observing and ordinary changes run, and the steps ibara recognizes as sending, spending, deleting or changing access wait for a person. An approval covers that one exact step. Pausing, Take Control, a restart or any change of access cancels any approval still pending.
Each request appears in the bottom-right corner of the console, in plain words, with Approve, Deny, Always Allow (for a send, spend or delete) and Details, which shows the exact request. A desktop notification offers Approve, Deny and Always Allow too.
In Chromium or Google Chrome, ibara recognizes a web form’s submit button, and Return in a form field, as sending even when the agent doesn’t say so; on the desktop, so is a click on a button named Send or Submit. It can’t recognize every send: a page that sends with its own script, or Return in a chat app, looks like an ordinary step unless the agent declares it. So give agents only computers where you’d let that agent work.
Turning approvals off
If you’d rather not be asked, turn off Ask before agents send, spend or delete in ibara’s Settings for every computer you manage, on one computer’s Settings tab, or for one agent in Access. Or answer an approval with Always Allow: that agent can take that kind of step on that computer without asking again, for as long as its computer may run agent tasks there. If you tell your agent it doesn’t need to ask, it asks ibara, and you get one request with Allow and Not Now. An agent can never change its own rules.
The switch covers agents from your own computers only. A friend’s agents keep asking unless you choose Always Allow for them, one at a time. Denied stays denied, and changes to access always ask.
One driver at a time#
Only one person or agent can drive a desktop at a time. An agent keeps control while it stays connected. It loses control when its session sends no heartbeat for five minutes (one goes every 30 seconds while it’s connected), or 30 seconds after it disconnects. A restart ends any agent’s control. The computer then resumes by itself once it’s healthy, unless a person paused it or its Resume agents after a restart setting is off.
Watch, take control, hand back#
- Watch: a computer’s Screen tab shows its screen without pausing the agent or taking input.
- Take Control pauses the agent, revokes its control, and only then lets your input through and starts the live stream.
- Hand Back ends your session, locks the stream again and makes the computer available. It never restarts an old agent session. Closing the viewer window does not hand back; you do that explicitly.
In the viewer, Super+Alt+Escape moves your keyboard between the two computers, and a tag says where keys go. While you have control, text and pictures you copy on either computer paste on the other (each computer’s Shared clipboard setting turns that off), and files you drop on the viewer are sent.
On two test computers (0.1.0-9, 28 September), 50 Take Control and Hand Back cycles in a row had no errors, no stuck keys and no viewer or stream left over. After Hand Back, the computer took an agent task again in 0.7 seconds (median of 40 tries).
Files#
Files you send from the console land in ~/Downloads/Ibara on the other computer, and the Files tab gets files only from that folder. An agent’s file tools work in its task’s folder or anywhere in your home folder, except ibara’s own folders. Every transfer is checked by size and SHA-256. Files you get or collect go to ~/Downloads unless you choose another download folder. Files you send or collect never overwrite an existing file. By default, an agent’s send, or a write that would overwrite a file, waits for your approval. Each computer takes files up to 250 MB unless you change its limit, and never more than 500 MB through the console. A bigger file is refused before anything is sent, with its size and the limit.
What leaves the computer#
- To your agent: screen images when the agent asks for them, cropped to what it needs unless it asks for the full screen, plus the text of what it observes. Your agent sends these to its model provider, as any computer-use agent does. Review your provider’s terms before working with sensitive information.
- To your other computers, as allowed: pictures of the screen while you watch it, and a live video stream only while you take control. Watching sends pictures, not the stream, and only while the console is open. Each card on the fleet wall gets a new picture every 5 seconds (2 to 60 in Settings), the computer you’re looking at gets one a second, and a screen that hasn’t changed sends almost nothing.
- With Live Video (Preview) on: each computer shows as live video on the fleet wall and the Screen tab, on computers with a hardware video encoder. It’s off by default. It is new and not yet stable, uses more memory and bandwidth, and falls back to pictures by itself. Video is refused while a person has Take Control, and each viewer’s video starts fresh when access changes, so nobody receives screen from before they were allowed.
- To ibara: nothing. There is no ibara cloud service and no telemetry. The input driver’s telemetry is switched off.
Task replays, small before-and-after pictures of each step, stay on that computer for 14 days (90 days for sends, spends, deletes, access changes and failed steps), up to 1 GB or 5 % of the disk, then are deleted. No picture is kept of typing into a password field.
LOCAL EXECUTION IS NOT LOCAL INFERENCE
The work runs on hardware you own. Reasoning runs wherever your agent runs, which is often a model provider’s servers.
What ibara is not#
ibara is not a sandbox. An agent with control of a desktop can do what a person at that desktop could do. Give agents computers, accounts and files that you are comfortable with them using, and keep sensitive work on machines they cannot reach.
Revoking access#
- Pause Agents stops all agent input at once.
- Remove Access, in the computer’s Access tab, takes away every permission that computer and its agents have there.
- Remove Pairing also ends the pairing, so that computer has to be added again.
- Revoke, in Share This Computer, ends a friend’s invite and the access it gave.
ibara uninstallremoves ibara from this computer but keeps its keys and pairings for a later install.ibara uninstall --delete-dataremoves those too, so other computers have to add it again. To take away one computer’s access, use Remove Access or Remove Pairing instead. Each of these is a separate step and does only what it says.