This post first appeared on the Bees blog.
Most agent platforms ask for your files. Upload the folder, connect the drive, grant the scope — then the work happens on someone else's computer. That is a reasonable trade when the files are a support inbox. It is a bad trade when they are contracts, payroll, patient records, or source code.
Bees draws the line somewhere else. Agent runs happen on your computer, against files in storage you already control. What synchronizes to Bees Cloud is coordination metadata: which process a work item sits in, which status it moved to, which agent picked it up, and relative filenames and paths. Not the file contents.
Why it is a boundary and not a setting
A privacy toggle is a promise about behaviour. A boundary is a statement about where the code runs. If execution happens on your machine, there is no server-side copy to leak, subpoena, or accidentally log — regardless of what any setting says.
That choice has consequences worth knowing before you adopt it:
- Your machine does the work. Throughput is bounded by your hardware and your model access, not by a plan tier.
- Coordination still needs the network. Teams that never connect still run, but they do not see each other's progress.
- Model choice is yours. Run local models, use an existing Codex or Claude Code subscription, or point at a model API. The file contents go wherever you point them — which is exactly why the decision stays with you.
Where this shows up in practice
The clearest case is a regulated team that wants agents but cannot move documents off managed storage. They keep the documents where compliance already approved them, install Bees on the machines that already have access, and get shared status across the team without the files ever becoming someone else's asset.
Start with Getting started, or read why Bees exists for the longer argument.
Top comments (0)