Trust

Keep repo execution local and make the work auditable.

DexCode should reduce trust risk by showing what happened without forcing every repo into a hosted execution environment on day one.

Boundary

What DexCode should hold

The control plane stores run metadata and evidence, not unlimited repo access.

Scoped tokens

Required

CLI and API tokens should be revocable, named and scoped to the account.

Evidence retention

Required

Artifacts need configurable retention because traces and screenshots can contain sensitive context.

Human approval

Required

Merge, deploy and customer-facing changes still need explicit owner approval.

Controls

Governance surface

Trust work belongs in the product, not in scattered docs.

Budgets

Planned

Set weekly and monthly limits by account, user and provider.

Audit export

Planned

Export run history, actors, tokens, PRs and evidence for review.

Private artifacts

Planned

Separate public PR links from private account-only evidence.

Shared app

Trust starts with clear access.

The consolidated dashboard makes it obvious who can use Dex and which account owns the work.

Open dashboard