Skip to main content

Community and hosting

Decision record: 22 September 2026. This consolidates the onboarding portion of #122, #411 and #475.

Community is the complete single-organization control plane. Hosted Community is the operated service with explicit resource limits; self-hosted Community is the same authority boundary without the hosted agent cap. Persistent access does not promise unlimited hosted compute, lifetime storage, a service guarantee or a new price.

PropertyHosted CommunitySelf-hosted Community
Initial accessReviewed/open signup, invitation and available capacity; once mode: open is enabled and qualified, initial access includes automatic verified signup: a person verifies an email and provisions their own empty workspace with no operator step. It remains review-mode, waiting on the founder's approval, until then (#243)Operator installation and quickstart
Workspace lifetimePersistent from claim; no 14-day trial conversionOperator managed
Agent creationExisting three-agent allowance; sleeping agents hold a placeUncapped by the software
Existing agents above the hosted capRetained; cap applies to new creation/reactivation, never a governed requestUncapped
AuthenticationOrdinary accounts and configured sign-in providersOrdinary accounts and configured sign-in providers
LearningOptional read-only synthetic example; advanced CLI demo only in a fixture-only workspaceSame optional example and fixture boundaries
ConnectorsOnly configurations actually supported by the deploymentOperator configures supported connectors
OperationsHosted capacity, dormancy, retention and abuse controlsOperator owns deployment and data lifecycle

The internal plan codes are compatibility values, not a new commercial offer. free means the hosted three-agent allowance; team is uncapped and remains the self-hosted default. Existing team tenants retain that allowance, including grandfathered onboarding records. Migration 0053 changes only legacy sandbox plans to free, without deleting or disabling existing agents. Do not infer a paid contract or an installation's hosting mode from a plan code alone.

Authority and integrations​

Policy, shared impact across agents and platforms, scoped human approval, audit and replay, ordinary OIDC, own-directory/log/Foundry metadata, open connector/executor interfaces, free SIEM sinks and replicas sharing the same authority remain Community commitments. A commitment is not evidence that every adapter or distribution artifact has shipped; see Integrations, Install and the issue board for delivery state. Existing safety is never a paid upgrade.

Execute uses a configured connector to dispatch. Gate supports an external executor while the customer retains its connectors and credentials. The dedicated Tines Gate kit is still #480; Community onboarding does not require managed credential custody or custom actions. Monitor supplies visibility and alerts, not execution authority. A direct credential outside a governed path can bypass it.

Enterprise differentiation is supported operation across independent estates, SAML/SCIM, managed custody and contractual services. Community replicas over shared PostgreSQL are distinct from that independent-estate control plane. This unit introduces no prices or purchase flow.

Persistence and administration​

Invitation expiry, credential/session expiry and approval expiry are independent of workspace access and remain enforced. Hosted dormancy remains the existing ninety-day governed-inactivity policy: agent principals may sleep while administrators retain access. Sleeping agents still count toward the creation allowance and can be woken without buying more authority. No advance dormancy email is currently promised. Signup contact retention and tenant/audit retention are separate; dormancy does not delete history. See Operations.

Public hosting remains subject to its published terms and approved deployment configuration. The optional seeded examples use synthetic data and protected mocks. This transition neither adds a real provider connector nor grants permission to use organizational systems.

Release and licensing status​

This document does not change the recorded licensing decisions: AGPL for the server, Apache for clients/connectors/protocol/packs and the separately recorded documentation license. License files, notices and the transitive inventory remain #122 work. Public repository/image release requires #237's authorization and evidence; an existing local Community install does not establish a published release. Hosted migration and public deployment of this onboarding change also remain separate release actions. Follow Community transition.