Agent on your site
One worker per client site for ops. Keys do not stretch across sites.
Ops on a client site use a per-site worker. Think one worker per client for that dashboard, not a shared actor that wanders every site you own.
One worker per client site
Each site has its own worker access. A developer who works on many clients mints a key per site. There is no cross-site key and no registry of agents across customers.
Keys stay on that site
The worker door is scoped to that dashboard: list, read, reply, and patch Requests for that site. Wake URLs are minted by hand per site. Nothing fans out on its own.
- Mint and revoke under Settings, Requests (admin or developer).
- The raw key is shown once. Copy it then.
- Revoke if that worker should stop. A revoked key cannot act.
Wake webhook
Optional. Admin or developer can save an HTTPS URL and a shared secret on the same Settings, Requests card. xTerminal POSTs a small wake when a new Request is filed, when a client replies while status is Needs a reply, when the owner accepts a preview, when someone asks to Ship to live, when a visible message lands on an open Request, and when a visible message mentions a person. Fail soft. Owners never see this form.
What the owner sees
The owner sees the Request move and the review card. They do not see the key, the webhook, or a brand name for the worker. If several people help, they still join as Team members with a rank.
Connecting the first worker
- Turn Show Requests on (owner or developer) once the site is entitled.
- Admin or developer mints a worker key.
- Optionally save a wake URL for that site.
- File a small Request and confirm the worker picks it up as Working.