Workspace isolation
Files and execution are organized by workspace, and the agent works only with context authorized for the current task.
Flowmint can read files, run commands, use authorized connections, and create deliverables. Permission boundaries, execution environments, and traceable activity are part of the product rather than hidden behind the chat.
Files and execution are organized by workspace, and the agent works only with context authorized for the current task.
GitHub, GitLab, and MCP connections require explicit configuration and enablement.
Connection credentials are stored and injected server-side rather than shown as messages, files, or ordinary tool arguments.
Messages, tool calls, errors, and file changes are recorded as events so users can review what happened.
Deployments can use Native, Docker, or Microsandbox backends with resource and network policies.
Dynamic pages can run services inside their workspace, while static deliverables need no extra process.
The agent can verify real output but does not bypass authentication, network policy, or site access controls.
Uploads, generated files, and intermediate artifacts can be viewed, downloaded, or deleted with the workspace.
What is sent to a model and how it is retained depends on the configured provider and deployment.
Deleting a workspace removes its application data and files; copies in external systems remain subject to their own policies.
This page describes current product boundaries. It does not claim security certifications or compliance commitments that Flowmint has not obtained. Private deployments can further control models, networks, storage, and sandbox policy.
Describe the goal first, then add files and external connections only when needed.