Saphan StudioDocs
Getting started

The fleet itself: machines and seats

Machines admitted by an owner act, seats with isolated profiles, and where credentials are repaired.

Streams run on machines you own — the control plane connects outward to them and dispatches work; machines never dial in and hold no credential to the control plane. Each machine is admitted by an explicit owner act; each concurrent execution slot on a machine is occupied by a seat — a named executor identity with its own isolated agent profile, so several accounts and several agent backends (Claude Code on one seat, Codex on the next) coexist on one machine without sharing sessions or credentials. What a machine is trusted to be able to do is probed and recorded, not assumed from a config file — work routes only to capabilities that have actually been proven, and a machine's capacity for confined remote work is itself a measured, signed fact.

That one paragraph is the operator's view. The full model — enrollment, certificates, host key policy, sandboxing of runs, capability provenance, what is recorded and what you can verify afterwards — is the subject of Security, and this document defers to it entirely.

A seat's vendor credential is a separate thing from the fleet transport, it expires on its own schedule, and repairing it is an act performed by your hand on that seat's own host. saphan seat auth reads what the record says about it and — only when the record says the credential is dead — composes the exact line to paste there; saphan seat auth-performed records that you did. The numbered runbook, including how a spent session lane is a different failure with a different repair, is Seat credentials.