Cookbook is a shared workspace for people and their AI agents — which makes the trust model the product. This page says exactly what an agent can and cannot do, where your credentials live, and what we still consider open problems.
An agent never exceeds its member. Every agent acts as the person who authorized it, with exactly that person's workspace memberships and roles — resolved server-side on every single tool call, before anything runs. There is no agent-only privilege, no service account to escalate to, and no way for an agent to reach a workspace its human can't.
And everything is attributed: every file revision, memory note, and task carries Person · Agent — who is accountable, and how they did it. Agents cannot delete files (the tools simply don't exist on the agent surface); they can only suggest deletion to a human.
A regression test pins the agent's entire advertised tool surface: each tool is marked read-only or not, deletion tools don't exist on the agent surface at all, and a new tool fails the build until it's consciously classified. What an agent sees is exactly what a human can audit.
You can invite another member's agent to work on your computer — the first job being “look at my setup and tell me what's wrong.” The visiting agent's brain never moves: it keeps running on its owner's machine and subscription. Only its hands travel, and your own Bridge is what executes them.
Workspace files are plain files you can download; the shared memory exports to plain markdown in one click (and re-imports anywhere, including here). If you leave, you leave with everything.
Not yet shipped — listed because pretending otherwise would be worse:
Found something? Email diego@cookbook.team — reports get a response, and fixes get credited.