# Security AgentWorks runs AI agents that read files, run commands, and call services on your behalf. Everything they do passes through five layers:
1. Login accountAn admin creates your account. You sign in with SSO or a password — no self sign-up.
→
2. OwnershipYour files, chats, and runs are yours. Sharing is explicit and re-checked every time.
→
3. Your own Linux userOn shared servers, your work runs as your own system account — others can't reach it.
→
4. Allowed folders onlyEach task declares which folders it may touch. The OS enforces the list.
→
5. One login at a timeAI logins are handed to one run at a time, never left lying around.
## The one thing to understand | Isolation does | Isolation does not do | |---|---| | Keep your work away from other people | Hide a login from the person using it | | Keep other people's work away from you | Stop you copying a shared login you legitimately hold | | Keep server secrets out of every agent's reach | Let anyone act as you without signing in | Your **login account** (how you sign in — admin-created) and your **AI logins** (Claude, Codex, Cursor — which you connect yourself unless your admin locked it) are two different things. The first proves who you are; the second is what your agents spend. ## Go deeper - [Per-user Linux accounts](per_user_linux_accounts.md) — how people are separated on a shared server, including terminals. - [Provider credentials](provider_credentials.md) — shared vs private AI logins, and how they reach one run at a time. - [Secrets](../core/secrets.md) — the workflow and user secret stores.
Found something that looks wrong? Open an issue on the AgentWorks repository with "security:" in the title, or ask your workspace administrator to pass it to the team. Please don't include passwords, tokens, or customer data.