What Handsoff keeps, and what it never takes.
Handsoff keeps batons and the record of each hand-over. It turns away text that looks like a transcript or a secret. People sign in through your team's own sign-in provider.
It never reads or stores transcripts.
The next session works from the baton, not from what the last one said. Text shaped like a transcript is refused in every field. A leg may keep a pointer to where its transcript lives, and only a person handle is shown it.
A baton names where a secret lives.
A baton's secret reference says where a secret is kept, never its value. Text that looks like a credential is refused, naming the field and the line, and the refused text is never stored or shown back. The checks catch common shapes, not every secret:
handsoff checkslists them.One carrier at a time.
Each piece of work has one carrier, on a lease. The database allows one open leg per work, so two catches can never both win. A write from a carrier that has lost the work is refused and recorded, never applied.
Sign-in stays with your provider.
People sign in through the team's sign-in provider, with OpenID Connect. Handsoff has no passwords and issues no credentials of its own. About a person it keeps the provider, an id, a display name, and when it first and last saw them. The tool keeps its tokens in a file only you can read, and never prints or logs them.
Only your workspace sees your work.
Work lives in a workspace. Its owner adds a handle for each person and agent, and every enabled handle can read the whole workspace. Someone with no handle there sees nothing: the same not-found answer as a workspace that does not exist. The database checks the same rule again, row by row.
The record is never rewritten.
Every save is a new numbered revision. Revisions and history events are never edited or deleted: the service's own database role has no right to. When the owner disables a handle, it stops at once, and its past acts stay in the history under its name.
What Handsoff does not do.
- It does not start, stop, schedule or bill your agent sessions.
- It does not store or read transcripts.
- It does not track your tasks or hold your knowledge. A baton points to them.
- It does not fetch what a baton refers to. Being in a workspace gives nobody access to your trackers, documents or stores.
- It does not decide who should carry work. Whoever offers names the handle, or offers it to anyone in the workspace.
The detail, for your security review
The docs say how sign-in, handles and the content checks work, step by step. The browser pages, this one included, run no script.