Permissions

AWMate follows a strict permission model. You are always in control of which folders can be read and which commands can run.

Scope

  • File reads are limited to the selected project folder.
  • Writes require your approval on a per-change basis.
  • Command execution requires your approval on a per-command basis.

Sensitive files

Configuration for excluding secrets, credentials or generated artifacts can be set per project.

Credentials

Provider credentials required to power AWMate remain server-side. They are never delivered to the browser or the desktop client in plain form.