Security & Governance
Helix is designed to be an autonomous engineer you can trust.
Approval gates
Every destructive or state-changing action is a proposal you approve. By default Helix cannot delete resources, deploy to production, or modify repositories without explicit consent.
Audit logging
Every tool call, credential access, and approval is recorded in the audit log. Enterprise teams can export logs for compliance reviews.
Secret handling
Provider tokens and API keys are encrypted per team. Agent logs and outputs are scrubbed to remove keys, passwords, and JWT-shaped strings before storage.
RBAC
Teams have Owner, Developer, and Viewer roles. Only Owners can add or rotate provider credentials and change plan settings.