Understand VECTA’s access boundaries
Know who can see a task, where tools run and when an action needs your decision.
Accounts and task visibility
Workspace membership and task restrictions are checked by the service, not only hidden in the interface. Connected computers have scoped, revocable credentials. Do not share your account or computer credentials with another person.
Tools and approvals
Agent actions run in the selected environment, with tools and approvals determined by the connection. Review an action before allowing it. A separate project worktree helps organize changes; it is not an operating-system security sandbox.
Provider data and private reports
Using a remote model sends the context required by that connection to its provider. Review your provider’s terms before including sensitive material. VECTA community bug reports are private to the reporter and administrators by default; do not put credentials into reports or public discussions.