concept · product guidePublicVersion current

Helm overview

Helm owns ClearPoint managed execution and the employee work plane, including Workbench conversations and runtime. Its current surfaces include supervised sessions, approvals, streaming, replay, handoff, and termination through a web cockpit and local bridge.

What this covers

The Helm bridge connects an enrolled device to the tenant control plane. Pairing and tenant approval establish the device relationship. An accepted heartbeat establishes current online state. A running local process without a server-accepted heartbeat is not enough to call the bridge online.

How it works

Sessions operate within declared capabilities and workspace roots. Approval remains explicit where the action requires it. Tenant audit evidence records the material control path.

Limits

Ownership of the work plane does not prove preventive enforcement. Helm may be described as enforcing a policy only for an exact action path with a separately authorized mandatory policy-enforcement point in the path, closed bypasses, and current allow, deny, error, argument-fidelity, target effect or non-effect, freshness, and drift evidence. No generally published Helm path currently meets that promotion bar. Observation, a configured preference, a decision receipt, or a user instruction is not runtime enforcement.

Next steps

The Helm bridge connects enrolled host devices to the tenant control plane. Ensure host environments meet verified configuration and credential-store requirements before deployment.

Use Helm when a team needs a supervised session with explicit device enrollment, tenant approval, bounded workspace access, and reviewable evidence. Begin by connecting one machine, then pair the bridge and run a small read-only session before broader use.

Report a problem with this page

Do not include secrets or customer data.


Doc ID
cpl.docs.products.helm.overview
Source
docs/canonical/product-doc-sources/helm/drafts/overview.md
Updated