The audits

Egress

Egress shows what a session read from outside the workspace, grouped by scope.

Egress is the audit of where a session reached beyond the workspace. Where Risk asks "what could cause harm," Egress asks "where did data go, and where did it come from" β€” the reach of a session, classified by scope.

What Egress records

Egress records where the session reached beyond the workspace: web hosts, MCP servers, network shell commands, and files read from outside the workspace.

Scope

Each destination carries a scope:

  • remote β€” it left the machine.
  • outside β€” it stayed on the machine but left the workspace (the JSON value is local).
  • unknown β€” the destination could not be classified.

Outside is a fact about a path; unknown is an admission; the two are never merged. Collapsing them would let a genuinely unclassifiable destination hide among benign local reads.

β„Ή
Files read count as egress

Reading a file from outside the workspace is egress with outside scope β€” reach doesn't only mean the network. A credential file read is both an Egress destination and a Risk row.