firm os
Docs

What can the installer do in our account?

It asks for ten Cloudflare permissions, holds the key an hour at most, never logs it, revokes it when the job ends, and deletes the plan.

The installer gets a key from the Allow, holds it only in the install's job for an hour at most, never logs it, and revokes it when the job ends. Afterwards it keeps the install's record: no key and none of the plan's people, but the Cloudflare account's name, which may hold an email address.

The permissions

The Cloudflare Allow page lists the ten scopes the installer asks for:

ScopeWhat the installer does with it
account-settings.readLists the accounts the Allow covers, and reads the one picked
user-details.readAsked for with the account read; the code calls no user endpoint
workers-scripts.writeUploads the nine Workers and the web app; deletes them on removal
workers-kv-storage.writeMakes the three key-value stores; deletes them on removal
workers-r2.writeMakes the bucket; empties and deletes it on removal
aig.writeMakes the AI Gateway default if the account has none
access-app.writeMakes the sign-in app for the firm's address; deletes it on removal
access-policy.writeSets that app's rule: who may get in
access-idp.writeAdds sign-in with email codes if the account has none
access-org.writeReads the account's Zero Trust team, or makes one

The installer is a public OAuth client using PKCE, with no client secret. Tick one account on the Allow page: the key covers every account ticked until it is revoked, and firm os goes into one.

The key

The plan

A plan holds the firm's name, a line for its agents, its email domains, and each person's name, email, role and admin flag. The Install link carries only the plan's number.

What the installer keeps

The AI Gateway default that the installer makes, when the account has none, keeps logs of model requests in your account, as firm os's own deploy expects. You can turn its logging off in the Cloudflare dashboard.

Updated This page as Markdown