Who controls what
The two modes run the same image; they differ only in who holds the configuration, the secrets and the host.
| Customer-operated | Privately managed | |
|---|---|---|
| Host, network, TLS | Your IT | The operator you contract, on infrastructure you name |
| Storage (database, stored files, backups) | Your volumes and backups | The operator’s volumes; backups delivered to you on request |
| Compute (calculations, runners) | Your host | The operator’s host |
| Models (AI use) | Only providers you configure; nothing by default | The same: only providers you approve |
| Access (who may read what) | Project administrators in your organisation | Project administrators in your organisation: the first administrator in config.json is your nominee; the operator places that first token and hands it over, and it should be replaced after first sign-in (a new token revokes the old one) |
| Operations (upgrade, restore, members) | Your operator, with ophiolite-ops |
The contracted operator, with ophiolite-ops |
| Exit | Portable bundles and backups, any time | Portable bundles any time; a backup or a project move to your own deployment on request |
What an operator can see. Whoever runs the host can read the database and the stored files: that is true of any server software. What Ophiolite adds is that access inside the product is by explicit grant, every change is recorded in the activity history, and a project can be moved or exported without the operator’s cooperation in the data format (bundles are readable without Ophiolite).
What Ophiolite (the vendor) sees. Nothing: the image sends no telemetry and needs no vendor account.
