Create a capture token for each developer
Each developer machine gets its own named capture token. A capture token can send data but can’t read it.- Stop Sediment.
-
For each machine, generate a token:
-
In a private editor, add one
SEDIMENT_INGEST_TOKENSline to~/.sediment/server/server.env. Its value is a JSON object that maps each machine’s name to its token:The namesoperator,legacy, andretrievalare reserved. Keep the file mode at0600. - Start Sediment.
-
Send each developer only their own token through a private channel. Keep
SEDIMENT_OPERATOR_TOKENand the rest ofserver.envto yourself.
SEDIMENT_INGEST_TOKENS object.
Connect your repositories
- Create the GitHub webhooks for Pushes, CI, pull requests, and repository changes.
- For private repositories, give the server read-only mirror credentials.
Install Sediment on each machine
Each developer runs these steps on a macOS or Linux machine with Git andcurl
on PATH.
-
Install the version that your deployment runs.
/healthreports it:If the installer prints aPATHinstruction, run it. Then check thatsediment --versionprints the same version. - Install and sign in to each agent through its normal setup. Start and close it once so that its configuration directory exists.
-
Enroll the machine. Replace the deployment URL, developer identifier, and
repository path:
login --captureprompts for the developer’s capture token.installconfigures every agent that it detects. If the developer doesn’t use Codex, omit--codex-profile sediment. Resolve everyFAILfromdoctor.
Verify capture
A/health response and organization-wide Fact counts don’t prove capture.
Check one real Session for each agent that the team uses.
-
On an enrolled machine, also sign in with the operator token, and create a
scratch branch:
-
Load
. "$HOME/.sediment/env.sh", and start the agent from that shell: -
Ask the agent to create a small file, and end the Session. Use Cursor
Agent rather than Tab, pi’s
writetool, and a single-file patch in Codex. -
Commit only that file, and read the commit’s Session note:
-
Copy the
session_idfrom the note, and check that Session on the server. Set--agenttocodex,cursor, orpi:Each check reportsok. If you enabled transcript or gateway capture, add--transcriptsor--inference-calls. Cursor supports neither flag. For Claude Code,doctor --agentisn’t available. Runsediment factsbefore and after the Session, and check thatdeveloper_decisionsgrew.
Verify forge delivery
Push the scratch branch, and check that the server linked the commit to its Session:refs/notes/sediment, and sediment commit lists the Session.
After the CI workflow finishes, the commit also shows its CI outcome. Merge
retention needs a real pull-request merge, so verify one before you read that
report.
Know what each agent captures
Agents supply different evidence, so compare them with care:- Cursor supplies neither Inference calls nor Edit observations.
- Cursor and pi accepts, and automatic Codex approvals, are implicit. Reports don’t count them as human-explicit accepts.
- Session-end retention needs Edit observations. Merge retention also needs pull-request webhooks.
- Missing evidence isn’t a negative outcome.
Remove a developer
- If the machine runs a sender replay worker, drain and stop it with Preserve prepared payloads through outages.
-
On the machine, remove capture from each repository:
To remove the machine-wide agent hooks too, follow Uninstall capture.
- On the server, revoke the token.