Enterprise
Give agents access to your code. Keep control of it.
Single sign-on, precise roles, a complete activity log and branches with no public address come with every workspace. Nothing on this page is an add-on.
Controls
01Identity
Sign in the way your company already does.
- Single sign-on over SAML or OIDC through your identity provider.
- Google, Microsoft, GitHub and Apple sign-in, each switchable per deployment.
- Authenticator-app two-factor, required for every organization by default.
- People with a verified company email domain join automatically; personal email domains never do.
- Sessions last at most seven days and end after a day idle; admins can revoke them.
02Access
Permissions as precise as your org chart.
- Workspace, organization and project roles, from read-only to admin.
- Custom roles built from allow and deny rules, where deny always wins.
- Roles granted to people, nested teams or service accounts.
- A documents-only role for people who should never see code.
- Branch rules: required reviews and checks, linear history, signed commits, no force-pushes, with named exceptions.
03Audit
Know who did what, and whether it was allowed.
- Every sign-in, push, branch change, review, merge, CI run and permission change is recorded.
- Secret, environment and settings changes, and every AI model call, are recorded too.
- Each entry records who, what, where, when and whether it succeeded or was denied.
- Owners and admins filter the log by action, person, result, organization and time.
04Isolation
Branches with no public address.
- The browser talks to one authenticated gateway; branches have no public network address of their own.
- Secrets are encrypted with AES-256-GCM, scoped to a project or environment, and never shown again after saving.
- Secrets reach a branch as a file read once and deleted, never as environment variables a terminal or agent could inherit.
- Admins can shorten how long a branch’s credentials live, down from a maximum of eight hours.
05AI
Agents on your terms.
- Each person can link their own Claude, ChatGPT or Google account; projects can hold their own API keys.
- Those credentials are encrypted and never sent to a branch; model calls are made on the person’s behalf.
- Choose the default coding agent per project: Claude Code, Codex, Gemini or the built-in agent.
- Agents work under the same permissions, branch rules and reviews as people.
06Hosting
Where it runs.
- ReasonOS runs on Google Cloud today, in the United States.
- Each cloud gets its own control plane, so your workspace and its data stay in the cloud you chose.
Coming soonDirectory sync (SCIM) · Audit log export · AWS and Azure · SOC 2 report
Talk to us
Bring your security questionnaire. We will answer it line by line.
Write to [email protected] and we will walk your team through how ReasonOS handles identity, access, data and agents.