Register the resource
Store a customer-safe server reference, purpose, ownership, and project relationship in the public application.
Infrastructure
DenOps is building a project-centered operating view where server references, Link Kits, health evidence, tasks, approvals, and outcomes stay connected without exposing private credentials or unrestricted access.
The intended workflow treats a server as a customer-owned project resource, not an invitation for an agent or browser session to gain broad authority.
Store a customer-safe server reference, purpose, ownership, and project relationship in the public application.
Use Link Kit as a narrowly controlled per-server component with explicit capabilities and no reusable credential in browser code.
Present useful health, task, and change evidence without leaking private addresses, credentials, internal paths, or unrestricted traces.
Require explicit Approve or Reject controls for sensitive work and preserve the decision with the project record.
A Link Kit is intended to connect one customer-owned server through a reviewed, narrowly scoped path. It is not browser shell access, a shared administrator credential, or a route around project permissions.
Projects remain primary: server references, requested work, approvals, deployments, activity, and customer-safe outcomes belong with the project that owns the objective.
See the controlled release path →These principles describe the infrastructure experience being built; they do not claim connected monitoring or execution is available today.
The browser never receives private service credentials, shell access, or a direct route to Link Kits, servers, or private Core.
Every request stays limited to the exact project resource and customer-granted capability needed for the task.
Customer views show bounded status and outcomes while private topology, secrets, hidden reasoning, and internal traces stay private.
A chat reply is never permission. Sensitive actions require separate, explicit Approve or Reject controls tied to the exact request.
The public application does not currently monitor or operate customer servers through private DenOps Core or Link Kits. Those capabilities remain disabled until the customer-safe gateway contract, scoped authorization, enrollment, approval validation, and response protections are accepted and tested.
We can discuss the workflow while staying direct about what DenOps supports today and what is still being built.