# Who may open what

> Per-machine access — a machine belongs to whoever connected it, you name who to share it with, and read-only is for people who should not have a terminal. A colleague who cannot see a machine is not on its list.

A machine you connect is yours. Colleagues do not see it until you share it.
Admins of the workspace always can.

This is a [Teams](https://beafk.app/docs/plans.md) feature.

## The default: you

You are named on it the moment it joins the fleet. Nobody else sees it on
their list until you name them — not a locked card, nothing at all.

Admins are the exception, and they always are: see below.

## Naming people

Tick the people who may open it. The list shows everybody in the workspace
rather than a search box, and saving sends the whole list at once.

**Naming people also hides the machine.** A machine with a list on it is not
merely un-openable by everybody else — it is **off their fleet entirely**. They
do not see a locked card; they see nothing.

So a list of two on a team of eight makes that machine private to those two
people. That is usually what somebody wants, and it is worth knowing before you
save.

## Opening a machine to the whole workspace

Take everybody off the list and save it empty. A machine nobody is named on can
be opened by everybody in the workspace — that is the one way to say "this one
is ours", and it is something you do rather than something that happens.

## Two levels

**Full** — running things, the variables, the agents. Everything.

**Read only** — the panel with its secrets shut. They can watch the machine and
read what it is doing, but they **cannot run anything, reveal a variable, or
change anything**.

Running things is why most people open a machine, so choose read-only
deliberately.

## Admins are not on the list

An admin of the workspace can open any machine whatever the list says. They can
rewrite the list in one press, and a machine whose list named no admin would
belong to nobody. The screen says so.

This is also why a machine being yours is a rule about your colleagues rather
than about the people who run the workspace: an admin can delete the machine and
mint the code for the next one, so a door that shut them out would not be one.

## Taking somebody off takes up to an hour

Untick somebody and we stop signing for them **immediately**. A browser already
inside a machine keeps the session that machine gave it for up to an hour —
the same rule everywhere here, explained once in
[cutting somebody off takes up to an hour](https://beafk.app/docs/reaching-your-machine.md#cutting-somebody-off-takes-up-to-an-hour).

## The record

Every open is written down. See [the access log](https://beafk.app/docs/the-access-log.md).

---

beafk documentation · Team · https://beafk.app/docs/who-may-open-what

In this section:
- Workspaces — https://beafk.app/docs/workspaces.md
- Inviting people — https://beafk.app/docs/inviting-people.md
- Who may open what — https://beafk.app/docs/who-may-open-what.md (this page)
- The access log — https://beafk.app/docs/the-access-log.md

Every page, one line each: https://beafk.app/docs/llms.txt
All of it in one file: https://beafk.app/docs/llms-full.txt
