Guarded terminal
PATH shims for common tools. Humans get convenient resolution; agent harness invocations do not inherit workspace secrets implicitly.
Agents leave the shim at launch
Workspace Agent, app menu, printed commands, and hand-typed claude, code, codex, cursor, or devin start without guard markers. The parent tab stays guarded.
Run authsia setup --repair once and open a new terminal first.
Active
Shim count is live in this tab.
Stale
Guard metadata and PATH disagree.
Inactive
Inside a launched agent session. Agent launchers start unguarded; they are not routed through workspace run.
Default tool families
npm, pnpm, yarn, python, pip, docker, aws, gcloud, az, kubectl, helm, terraform, tofu, terragrunt, pulumi, ansible-playbook.