Egress
Egress shows what a session read from outside the workspace, grouped by scope.
Egress is the audit of where a session reached beyond the workspace. Where Risk asks "what could cause harm," Egress asks "where did data go, and where did it come from" β the reach of a session, classified by scope.
What Egress records
Egress records where the session reached beyond the workspace: web hosts, MCP servers, network shell commands, and files read from outside the workspace.
Scope
Each destination carries a scope:
remoteβ it left the machine.outsideβ it stayed on the machine but left the workspace (the JSON value islocal).unknownβ the destination could not be classified.
Outside is a fact about a path; unknown is an admission; the two are never merged. Collapsing them would let a genuinely unclassifiable destination hide among benign local reads.
Reading a file from outside the workspace is egress with outside scope β reach doesn't only mean the network. A credential file read is both an Egress destination and a Risk row.