Manage · Settings

Set the data boundary before connecting RepoOps

Settings combines local runtime controls with account, repository, and team connections. Decide what RepoOps may capture and send first, then wire only the inputs and destinations the work needs.

For: the developer configuring one RepoOps installation, and the team owner or admin reviewing connected hosted controls

What it does, and why it helps

The served Settings tab groups controls under App, Brain & sync, Privacy & keys, Team & MCP, Advanced, and Repos & accounts. Most local changes take effect at runtime. Repository and account rows use the local database, keys use the data-directory environment file, account settings use the brain settings store, and advanced navigation switches use browser local storage.

Treat the page as a boundary map rather than a setup checklist. Telemetry privacy defaults to Metadata only. Activity streaming, cloud sync, lesson sharing, and hosted publishers are separate paths. Connecting to a team is an explicit consent step, starts the capture daemon on a best-effort basis, and turns on publish rows that have never received an answer. A row explicitly switched off stays off.

The pain. A connection can look like one switch even when capture, storage, streaming, cloud sync, and hosted publishing follow different gates.

The point of view. Set the data boundary before the destination. Read the effective capture mode and the post-redaction preview, then connect a key, repository, or team and verify the resulting state.

What gets easier. Inspection. The page shows masked key status, tracked repository and account rows, team consent, daemon publishing state, and the independent sharing controls in one grouped surface.

When it helps. Use it during first setup, before connecting a team, when changing what leaves the machine, or when a repository, credential, or publisher needs review.

Its limits. Settings does not make every control account-wide. Browser visibility switches are per origin, repository tracking is local, and hosted /team/settings carries separate authenticated team controls.

Understand it in 30 seconds

30.1 s, captions on. Narration: Microsoft Zira Desktop (provisional voice; an approved narration source is pending).Transcript
Read the narration
  1. 0:00 A setup screen can turn into accidental sharing with one careless connection.
  2. 0:06 Decide what may leave first, then connect repositories, keys, and the team.
  3. 0:13 RepoOps shows the effective mode, the redacted preview and the masked key status.
  4. 0:18 Then team consent, daemon state and the publishing rows.
  5. 0:23 Wire only what the work needs, then verify every resulting reported state.

Synthetic example. Read the guide

Where to find it

Where to find it

  • Desktop: localhost:4000, then Local settings in the sidebar, under Workspace tools.
  • Hosted: repoops.ai/team/settings, from Team & settings in the sidebar, under Workspace tools.
  • Keyboard: ⌘ K, then type “Settings”.

When to use it

Connect a repository without editing a config file

Situation. A local Git repository already exists inside the managed workspace, or a GitHub account is ready to clone selected repositories.

What you do. Use Connect with the RepoOps GitHub App, or use Add a repo manually with Repo path (absolute). Assign the resulting Tracked repos row to an account.

What you see. The repository appears under Tracked repos. The runtime route validates a local Git repository, creates its RepoOps mirror, and indexes it without a server restart.

What it establishes. The repository is available to local RepoOps surfaces under the selected account. Adding it does not turn on team publishing or capture hooks by itself.

Review the boundary before connecting a team

Situation. The device has a one-time code and the operator needs to know which team and which activity fields the connection covers.

What you do. Open Telemetry privacy, choose Metadata only or Content (redacted), press Preview what's shared, then enter the code under Connect to team and read the consent card.

What you see. The code preview names the team before the code is spent. The disclosure lists session timing, repository areas, tools, token use, and spend. The publishing row reports the daemon's live state after binding.

What it establishes. The device records a team binding after consent. Previously unanswered hosted publisher rows may turn on at this step, while explicit off choices remain off.

Give local model features an Anthropic key

Situation. A BYOK feature needs Anthropic access and the running process has no usable key.

What you do. Paste the key under Anthropic API key, select Save key, then use Test. Read the masked value and source before replacing or removing it.

What you see. The status endpoint returns a mask and source, never the key. Save writes ANTHROPIC_API_KEY to the data-directory .env and updates the running process. Test makes a token-free models request.

What it establishes. The running installation can use the saved key without a restart. A key supplied outside the managed data file must be changed at its external source.

Before you start

Supported versions
RepoOps desktop v0.3.1, the release this guide was read against.
Where it runs
Local: Local settings in the sidebar, under Workspace tools. Hosted: Team & settings in the sidebar opens /team/settings, an authenticated reconciliation page for account, governance, SSO, share links, cloud audit, operator config, alerts, aliases, and incident controls.
Permissions
Local repository and account writes require a same-origin request. Sensitive local writes also require the operator confirmation secret when REPOOPS_OPERATOR_CONFIRM_SECRET is configured. Hosted cards apply their own session and role checks.
Connections
Repository add needs a local Git checkout or GitHub connection. Team binding needs a one-time code from repoops.ai. A machine that chose Continue offline on first start signs in later from Sign in to repoops.ai under Team & MCP, which opens the same one-time-code sign-in page. Anthropic features need ANTHROPIC_API_KEY, but the Settings page itself makes no model call.
Plan
Not provided. Settings has no shared product-plan gate. Individual hosted capabilities can report their own subscription or role state.

Configure it

  1. Choose the capture boundary.

    Under Telemetry privacy, Metadata only drops prompt and assistant text before egress. Content (redacted) includes those fields after client-side redaction. A team policy can pin Metadata only.

  2. Inspect the post-redaction sample.

    Preview what's shared reads recent activity for a tracked repository and renders the effective mode, dropped-content count, redaction counts, and sample records before a streaming decision.

  3. Add local inputs.

    Add repositories, accounts, and an Anthropic key only where needed. Verify each tracked repository row and use the key test rather than treating a saved mask as provider proof.

  4. Connect destinations last.

    Read the team named by the code and the shared activity disclosure. After connecting, review Publishing, Cloud sync (hosted), Stream to your team, lesson sharing, and What this machine publishes to your team as separate controls.

SettingWhereA sensible choiceWhy it matters
telemetry.capture_modePrivacy & keys, Telemetry privacymetadata (the default); content is the other choice unless team policy pins metadataSets which fields prepareForEgress keeps. The page reports the effective and local modes separately.
ANTHROPIC_API_KEYPrivacy & keys, Anthropic API keyUnset until supplied through the environment or the data-directory .envEnables features that call Anthropic. Settings returns only a masked status value.
github.managed_rootRepos & accounts, Managed workspace rootC:/Projects (the default); choose another absolute managed rootBounds GitHub clones and manual repository adds for the runtime repository flow.
cloudSyncBrain & sync, Cloud sync (hosted)Off for an unbound install; an explicit opt-in or the bound-team default can make it effectiveControls two-way sync of the redacted local event store. Egress still needs a device binding. Under the bound-team default, only repositories you accepted your team's managed policy for send events; your own opt-in sends every tracked repository. The card lists each repository and why it sends or stays on the machine.
daemonEnabledBrain & sync, Capture daemonOn by default; REPOOPS_DAEMON_DISABLED=1 pins it offStops or permits background capture. It is separate from cloud sync, which gates upload of captured events.
REPOOPS_TRANSCRIPT_RETENTION_DAYSPrivacy & keys, Prompt and response recording30 days (the default and the ceiling); 7 or 14 days to keep lessSets expiry for captured prompt and response payloads and for the prompt and reply text kept on every session record. Turning recording off does not delete existing history.
repoops.labsAdvanced, Show Labs tabs (experimental)Off when the browser local-storage key is absent; on stores 1Changes Labs navigation visibility for the current origin and reloads the dashboard.
repoops.powerUserAdvanced, Show power-user tabsOff when the browser local-storage key is absent; on stores 1Changes power-user subtab visibility for the current origin and reloads the dashboard.
ⓘ
To stop or undo
Not provided as one global control. Turn off the capture daemon to stop new background capture, disable each sharing path independently, or disconnect the team binding. Existing local and hosted history is not deleted by those switches.

What you should see

Local metadata boundary

Configuration. Telemetry privacy is Metadata only, Stream to your team is off, cloud sync is off, and the device is unbound.

Expect. Captured activity stays local. Prepared egress records omit prompt and assistant text, and the preview reports content dropped.

Verify. Press Preview what's shared and read the mode and sample. Confirm the team row is unbound and each sharing control is off.

Repository tracked under a client account

Configuration. A valid local Git path is added and its Tracked repos account selector names a non-default account.

Expect. The repository appears in the runtime repository list and its current account id drives account-scoped rollups.

Verify. Reload Settings and confirm the repository row, path, branch, and account. Historical JSONL is not rewritten when the account assignment changes.

Team-bound device with visible publishing state

Configuration. A valid one-time code is previewed, consent is checked, and the device connects.

Expect. Settings shows Team, Plan, License, Connected, and Publishing. The bind attempts to start the daemon and activates unanswered publisher rows.

Verify. Read Publishing for streaming, first push pending, paused, not reaching, not running, or unknown. Inspect each publisher row rather than inferring delivery from a valid license.

Data and cost

What is captured
Repository and account records live in the local SQLite store. Managed keys live in the data-directory .env. Capture mode and publisher choices use local key-value or account settings stores. Prompt payloads, when enabled, remain in the local capture store until their retention sweep applies.
Who can see it
Metadata mode can send counts, timings, tools, tokens, cost, and paths, but not prompt or assistant text. Content mode can also send redacted prompt and assistant text. Streaming, cloud sync, lesson sharing, benchmark contribution, and hosted publishers are separate paths with separate status.
How long it is kept
Prompt and response payloads, and the prompt and reply text on session records, offer 7, 14 or 30 days. A window saved as 90 days or keep forever runs at 30. Not provided for repository records, account records, local aggregate telemetry, or hosted activity from this page.
What leaves the machine
No egress is required to render Settings. Tests and connections call their named providers. Team publishing needs a binding and its applicable toggle. The egress preview runs the same local preparation used for activity records.
What it costs
Settings makes no model call. The Anthropic key test uses a token-free models request. Provider-backed features configured here can have their own model or service cost.

When the result differs

SymptomLikely causeNext action
A saved Anthropic key still cannot be used.The value can be malformed, externally sourced, or refused by Anthropic. A saved mask alone is not a live provider check.Use Test. Replace a managed data-file key in Settings, or change an external key at the environment source reported by the status row.
Content (redacted) cannot be selected.The bound team pins metadata-only capture, so the local choice cannot loosen that floor.Keep Metadata only. Ask the team owner about the hosted policy if content capture is required.
The team license is valid but no data arrives.Binding, daemon state, capture, cloud sync, streaming, and publisher toggles are independent. The daemon can also report a block or push error.Read Publishing on the bound team card, then inspect Capture daemon, Cloud sync (hosted), Stream to your team, and the relevant publisher row.
A repository path is refused.The path is not a valid Git repository or falls outside the managed workspace allowed by the route.Choose a Git checkout under Managed workspace root, or connect through GitHub so RepoOps clones it there.
Labs or power-user tabs do not appear immediately.Those switches use local storage and the dashboard reads them while rendering navigation.Allow local storage for the current origin and let Settings reload the dashboard after changing the switch.
Disable
Not provided as one feature switch. Disable capture, streaming, cloud sync, lesson sharing, benchmark contribution, and publisher rows independently.
Roll back
Not provided as one rollback. Re-enter the prior value for an individual control. Settings does not keep a unified change history across its database, environment file, brain settings file, key-value store, and browser storage.
Revoke access
Use Remove key for a managed Anthropic key, GitHub disconnect for its local authorization, or Disconnect for the team binding. Team disconnect attempts server revocation and forgets the local binding, but hosted activity history is retained.
Delete
Repository Remove stops tracking and removes the RepoOps mirror, not the manually added source checkout. Deleting a non-default account moves its repositories to Personal and keeps telemetry history. No whole-Settings data purge is provided.

Maintenance evidence

Feature id
settings (spine leaf settings)
Owner
Runtime repository management, BYOK settings, and desktop team binding programs; Guide: LDG-0717
Supported product version
RepoOps v0.3.1
Last verified
2026-09-15, read against origin/main at 52366bb6d; labels read from the served tab source; local route handlers and hosted Settings scope also checked
Example fixtures
lib/byok.test.mjs; lib/byok-data-env-load.test.mjs; lib/routes/repos.test.mjs; lib/routes/repos-workspace-root.test.mjs; lib/routes/account-write-gate.test.mjs; lib/routes/connect.preview.test.mjs; lib/routes/publish-toggles.test.mjs; lib/routes/publish-toggles-bind.test.mjs; lib/routes/sharing-preview.test.mjs; lib/account-settings.test.mjs; lib/transcript-retention.test.mjs; website/lib/sharing-preview-hosted.test.ts
Source references
lib/canonical-spine.json, lib/canonical-tabs.mjs, public/settings.html, lib/routes/settings.mjs, lib/byok.mjs, lib/routes/repos.mjs, lib/github/clone.mjs, lib/routes/account.mjs, lib/db.mjs, lib/routes/telemetry.mjs, lib/redact.mjs, lib/routes/transcript-settings.mjs, lib/routes/connect.mjs, lib/auth.mjs, lib/routes/publish-toggles.mjs, lib/account-settings.mjs, website/app/team/(home)/settings/page.tsx
Documentation review
Independent review requested on the slice pull request; not yet recorded.
Video review
Story script written 2026-09-15; render and review pending in the same slice.

Last updated