Where this workspace's agents run, and how they reach back into the OS. Both halves are yours: the runtime is a host you control, and every key is scoped to this workspace alone.
The host your agents run on. Point the OS at a gateway you control — the URL and token are checked with a real handshake before anything is saved, and the token is encrypted in the vault, never sent to the browser.
How an agent, the gsjos CLI, or any MCP client reads and writes this workspace. A key acts as a workspace agent member — it is held to the same row-level permissions as a person, so it can never reach another workspace.