Filesystem confinement
Only the conversation workspace and its dedicated runtime state enter the rootless container.
Confinement is the product
Agents are useful because they can act. ChannelGate makes that action explicit: every conversation has an isolated runtime, approved people, selected tools and a visible operating mode.
What this enables
Only the conversation workspace and its dedicated runtime state enter the rootless container.
Approved users, guests and administrators have distinct, inspectable rights.
Modes, MCP connections and skills are granted at the channel boundary.
Approvals, work history and administrative changes remain reviewable.
Read the threat model and operating guidance in the public repository.
Explore security documentation →Self-hosted by design
ChannelGate runs the agent inside a conversation-specific rootless container. The hosted customer platform issues licenses; configuration, credentials, work and history remain with the deployment you operate.
Put it to work