Saphan Studio documentation
Saphan Studio is a control plane for governed fleets of AI coding agents: install it, connect your agents, and run work that a human decides and the record can prove.
Saphan Studio is a control plane for governed fleets of AI coding agents. Agents do the work on machines you own; every change waits for a human decision, and what happened is written into a record you can read afterwards.
This is the operator's documentation: how to install it, connect it, run it, secure it, and answer for it.
Start
| Task | Go here |
|---|---|
| Install it and reach the first working screen | An install, end to end — one command, what it verifies before it writes anything, and the address it leaves you at |
| Set up the first machine | First run at /setup — six screens in a browser, including the key ceremony that does not repeat |
| Run the first governed stream | Install, found the fleet, run the first stream — from an order to a human gate to a recorded result |
| See which agents and systems are supported | The agents it drives — the backends, and what has been exercised on which platform |
Operate
| Task | Go here |
|---|---|
| Read the fleet from a screen | The console — the owner's view of the record, and the small number of acts it offers |
| Decide a gate, land a change | Working with git — orders, returns, verdicts and merges |
| Control what it spends | Cost management — the quote, the cap, and what stops a run |
| Understand a refusal | Troubleshooting — the product refuses in words; this says what each set of words means |
| Look up a command | Command reference — every verb and flag, generated from the binary |
Deploy and connect
| Task | Go here |
|---|---|
| Choose a deployment shape | Deployment — which programs each machine gets, and which run centrally |
| Decide the settings with no default | Configuration — the values you must choose, separated from the ones you can leave alone |
| Establish who acts | Identity — how a person or a machine is identified, and what that identification is worth |
| Connect it to your systems | Integrations · Notifications · MCP server |
Govern and prove
| Task | Go here |
|---|---|
| Review the boundary | Security — what the product defends, and what it leaves to you |
| Answer an auditor | Audit and compliance — what the record proves, and where that proof stops |
| See what a run is allowed to reach | Egress control — what happens to a connection leaving a run |
Choose by your job
| You are | Start here |
|---|---|
| The person who owns the decision to run this product | For the owner |
| The person who installs it and is paged when it stops | For devops |
| The person accountable for what it spends | For the finance controller |
| The person who must establish what happened and whether the record holds | For the auditor |
| The person who signs off on the boundary | For the security officer |
Understand it first
If you would rather read before you install: Concepts is the vocabulary the product uses and what each word is doing in it, and Actors and roles is who — and what — is allowed to act.
⚠ Where a chapter stops short, it says so on its own page. Some capabilities are built and not yet exercised on every platform, and some are not built at all; those pages state which, rather than leaving a reader to infer it.