Once ChatGPT or Claude can edit files and run commands on your computer through MCP, using it alone is easy. Sharing it with a team raises questions fast:
- Who asked the AI to do what, on which computer?
- What if a command the AI ran had an API key in it?
- Where do you see what someone did after they left the team?
Disclosure: I'm the maker of BCD, a hosted remote MCP server that lets AI apps work on your own Mac, Windows or Linux computer. This week I shipped a team activity log, and these are the decisions behind it.
The setup
- Each computer runs a small agent that only opens an outbound connection to a relay. No ports are opened.
- AI apps (ChatGPT, Claude, Codex) connect by adding
https://bcd.snack-wrap.com/mcpas a connector. - In a team, each member shares computers they paired.
Two layers of permissions
- What the computer's owner allows: read / write / run commands / control the screen / clipboard. A new computer starts read-only.
- The member's team role: admin (everything, plus managing members), builder (read, write, run commands), viewer (read).
A member gets the narrower of the two. A builder on a computer its owner left read-only can only read.
What the log records
Every call on a shared computer is recorded, including the owner's own:
- who, on which computer, through which AI app (ChatGPT, Claude…)
- what they did (ran a command, read a file, deleted files…), the result, why it failed, how long it took
- the files and folders, web addresses (without their query) and commands the call named
- team changes: invitations, joins, role changes, removals, shared computers
Never recorded: typed text, file contents, clipboard contents, output.
Admins filter by member, computer, result and period, search by file path or command, and export CSV. The team owner picks how long entries are kept: 30, 90, 180 or 365 days. Only admins can see the log.
Secrets are masked before anything is stored
Commands an AI runs tend to carry tokens. These are real outputs of the masking code:
curl -H "Authorization: Bearer eyJhbGciOi..." https://api.example.com
→ curl -H "Authorization: *** ***" https://api.example.com
export OPENAI_API_KEY=sk-proj-... && npm test
→ export OPENAI_API_KEY=*** && npm test
psql postgres://me:s3cret@db.example.com/app
→ psql postgres://me:***@db.example.com/app
https://api.example.com/v1/orders?token=abc
→ https://api.example.com/v1/orders?…
Decisions worth stealing
-
Allowlist the arguments you read. The log reads only named arguments such as
path,commandandurl. Fields likecontent,textorinputare never read, so a new tool can't leak file contents into the log by accident. - Snapshot names. Entries keep the person's email and the computer's name at the time, so they still read correctly after a member leaves or a computer is removed.
-
Defuse CSV formulas. Cells starting with
=,+,-or@get a leading', so a spreadsheet never runs them. - Rows, not a wide table. Each entry reads top to bottom: what happened and its result, what it named, then who, where, when. It works on a phone without sideways scrolling.
Try it
One computer stays free; the first month covers 3 computers with no card. Paid plans and the free month can try a team of 3.
What else would your team need before letting an AI work on shared machines? I'd like to hear it in the comments.
Top comments (0)