A developer
Runs Claude Code against a real, isolated workstation, not a laptop with unscoped access to everything else.
Now in private beta
Developers describe the environment they need, tools and access included, in a file they can hand to a teammate or an agent. Security sets the limits that apply to every environment, so a developer never has to ask and an agent cannot exceed them.
AI agents are already running against your codebase, on developer laptops and in ad hoc containers, inheriting every permission scoped for the people you actually trust. That leaves two bad choices: approve every action by hand and lose the speed, or accept the risk and keep it.
A sandbox gives an agent somewhere to run. A Ringleader workstation is somewhere a team works: declared in a file, handed to a person or an agent, and still there tomorrow. An agent runs unattended inside it, reaching only the destinations you allow, with its API credentials held at a gateway in your cloud rather than on the machine.
Declare the machine, the tools, and the AI agent your project needs, then apply the file. Ringleader builds the same workstation every time, on a laptop or in your cloud.
# my-workstation.yaml
apiVersion: workstations.ringleader.dev/v1
kind: Workstation
metadata:
name: my-workstation
spec:
image:
os: linux
distribution: debian
packages:
- git
- curl
devtools:
- name: nodejs
- name: claude-code
- name: vscode-web
ports:
- 8080$ rl apply -f my-new-great-dx.yaml
workstation/my-new-great-dx created
$ rl apply -f my-new-great-dx.yaml
workstation/my-new-great-dx unchangedDeclarative, like kubectl. It stays persistent, so you
can close your laptop and pick up where you left off, or share the file
and a teammate or an agent gets the identical environment.
The same governance that satisfies a security review is what makes it safe to hand to people who aren’t engineers at all.
Runs Claude Code against a real, isolated workstation, not a laptop with unscoped access to everything else.
Vibe-codes a working prototype in a workstation handed over ready to run, with the same limits a developer's has. No setup, no IT ticket.
Gets a real workstation of its own, not a container someone started by hand, with the same limits a developer's has.
Six properties, one environment, for people and agents alike.
Isolation limits what a compromised agent can reach. Inside that boundary it reaches only the destinations you allow, and your API keys stay at a gateway in your cloud.
Agents get a real, first-class environment with the same guarantees a human developer has: the same boundary, the same limits, no drift.
Every environment is defined in code, so it rebuilds identically on any machine: yours, a teammate's, or an agent's.
Local environments pick up right where you left off. Cloud environments never stopped: kick off a job, close the laptop, and it's done when you sit back down.
Run the same definition on a laptop, in your cloud, or in a teammate's account: the same environment wherever it lands.
Spin up a ready-to-run workspace in minutes, not the days that onboarding and dependency wrangling usually take.
Start with a single developer today. The same environments become your organization’s control plane tomorrow.
Org-wide defaults with team and personal overrides, set in the same declarative config as everything else.
Every agent gets a single-purpose identity with the minimum permissions for its job: scoped, revocable, and never shared across tasks. Every action it took is reviewable.
Agent traffic leaves the environment only to destinations you've allowlisted, so a prompt-injected agent has nowhere to send what it finds.
Run the control plane in your own cloud, so code and state never leave your boundary.
We’re onboarding teams in small batches during private beta. Join the waitlist and we’ll reach out as spots open.
You’re on the list
We’ll email you as beta spots open.