In a local setup the CLI works against a checkout on the engineer's machine, under their account and inside the sandbox and approval policy you configure. The cloud agent works on a clone in an environment OpenAI hosts, with its own setup steps, secrets and network rules. The IDE extension and the desktop app can be connected differently, so where they run is established per setup, not assumed. A policy written for one doesn't carry over to the other, so we scope each surface you plan to use on its own.
Where prompts and repository context go depends on the provider that is actually configured: OpenAI's models, or another provider or a locally served model where the CLI is set up for one. A local runtime is not by itself a guarantee that nothing leaves the machine. What is sent, under which account and with what retention depends on the working surface, your configuration and your agreement with the provider. We document the flow as configured for each surface, and your data and contract owners check it against that agreement and the provider's current documentation.
- Sandbox mode and approval policy per repository: what runs unprompted, what asks first, what is off
- Network access from the sandbox and, where it is on, the registries and services the build needs
- Account type, model access and who administers them
- Shared settings in versioned configuration instead of per-laptop defaults
- Repositories and data in scope, agreed before the pilot