Skip to main content

Local execution

Local agents run on your computer with your native agent account and configuration. Your project selection tells the agent where to work; the harness’s permissions and operating-system controls determine what it can access. Choose Ask me to review tool permission requests, Approve for me to allow those requests automatically, or Full access to remove harness sandbox restrictions. Questions and plan approvals still require an answer. See local permissions. Local execution uses Twill for sign-in, coordination, conversation history, and agent output. It isn’t an offline or on-device-only mode. The harness sends model requests to its provider using your account. Native logins stay on your computer. The local file viewer reads files directly without uploading their contents to Twill; files included in agent output, attachments, or shared results can still leave the computer.

Cloud execution

Cloud work runs in the workspace’s sandbox. Tasks normally fork its main environment, separating their filesystem changes from other tasks. Fork off intentionally runs in the shared main environment. Cloud agents have full access inside the sandbox. Connected integrations, environment variables, and provider keys determine which external services they can use. Forks can still reach the same external services when they inherit the same credentials. Cloud implementation instructions call for task branches and pull requests by default. Those instructions aren’t a replacement for GitHub branch protection or service-level permissions. Review changes before merging, and grant only the access your workflow needs.

Handoff and secrets

Handoff pushes Git branches and sends a brief to a task in the destination cloud workspace. That task is visible to the workspace’s members. Local project chats remain in your private personal workspace. Cloud setup asks before copying local environment values. Approved values become available in the shared environment and future task forks. Agent logins, running services, and local databases aren’t automatically copied by handoff.

Stored credentials and access

  • Saved environment secrets and integration OAuth tokens are encrypted at rest using AES-256-GCM.
  • Workspace API keys are hashed at rest, scoped to their workspace, and rate-limited. A key stops working when its creator leaves the workspace.
  • Each cloud agent run gets its own sandbox API key so the agent can use the Twill API. Anyone who can run commands in the sandbox can read it, so it expires 12 hours after the run starts.
  • Workspace roles control team administration. Only the computer’s owner can control its local runs.
  • Model requests use either Twill-managed credentials, your cloud BYOK configuration, or your local native account. Provider data handling follows the applicable account and service terms.
For data handling and retention information, see the privacy policy. For team access, see Team management.