Helm overview
Helm owns ClearPoint managed execution and the employee work plane, including Workbench conversations and runtime. Its current surfaces include supervised sessions, approvals, streaming, replay, handoff, and termination through a web cockpit and local bridge.
What this covers
The Helm bridge connects an enrolled device to the tenant control plane. Pairing and tenant approval establish the device relationship. An accepted heartbeat establishes current online state. A running local process without a server-accepted heartbeat is not enough to call the bridge online.
How it works
Sessions operate within declared capabilities and workspace roots. Approval remains explicit where the action requires it. Tenant audit evidence records the material control path.
Limits
Ownership of the work plane does not prove preventive enforcement. Helm may be described as enforcing a policy only for an exact action path with a separately authorized mandatory policy-enforcement point in the path, closed bypasses, and current allow, deny, error, argument-fidelity, target effect or non-effect, freshness, and drift evidence. No generally published Helm path currently meets that promotion bar. Observation, a configured preference, a decision receipt, or a user instruction is not runtime enforcement.
Next steps
The Helm bridge connects enrolled host devices to the tenant control plane. Ensure host environments meet verified configuration and credential-store requirements before deployment.
Use Helm when a team needs a supervised session with explicit device enrollment, tenant approval, bounded workspace access, and reviewable evidence. Begin by connecting one machine, then pair the bridge and run a small read-only session before broader use.
Report a problem with this page
- Doc ID
cpl.docs.products.helm.overview- Source
docs/canonical/product-doc-sources/helm/drafts/overview.md- Updated