Access control
Every team member. The right level of access.
DetachDev's RBAC system lets you define exactly what each team member can do — from read-only session observers to team admins with full device management rights.
Granular RBAC
Assign roles per user: view sessions, send prompts, approve permissions, manage devices, or administer the organisation. Each action is gated by role.
Shared device pools
Register your fleet of dev machines centrally. Team members access the machines they're permitted to — without needing individual credentials for each one.
Session policies
Define limits per device or per user: maximum concurrent sessions, allowed project directories, time windows, and permission escalation rules.
Revocable access
Remove a team member's access instantly. Session tokens expire on revocation. No lingering SSH keys, no shared passwords to rotate.
Audit & compliance
Every action, attributed and logged.
DetachDev logs every session action at the platform level — not just what Claude Code® did, but who asked it to do it. This is the compliance story that individual developer tools can't provide.
Immutable audit log
Every prompt, permission approval, session start and stop is recorded with user, timestamp, session ID, and device. Tamper-evident by design.
SIEM export
Export logs to your security information and event management system. Compatible with standard log formats for ingestion into Splunk, Datadog, or your existing toolchain.
Session history & search
Full-text search across all session history. Find which session touched a file, which user approved a permission, or what Claude Code® output at any point.
Legal hold & DSAR
Freeze session records for legal proceedings. Export individual user data for DSAR requests. Available on Business and Enterprise plans.
Questions
Frequently Asked Questions
Can multiple developers share access to the same Claude Code® sessions?
Yes. DetachDev's multi-user RBAC lets team members access sessions on shared device pools with individually controlled permissions. All actions are attributed to the user who took them.
How is access revoked when a team member leaves?
Removing a user from the organisation immediately revokes all their session tokens and device access. There are no shared SSH keys or credentials to rotate.
Which plan includes team features?
Multi-user RBAC is available on Team and above. Audit logging, SIEM export, and legal hold are on Business and Enterprise. See full plan comparison →
Does the security model change for teams?
No. The core principle stays the same: your source code never leaves your machines. DetachDev relays commands and output only. Read more about security →