Forge documentation
Forge gives technicians and their external agents authorized access to customer devices, with explicit diagnostics, customer context, case notes and customer-message drafts prepared for review.
These guides describe the released Windows and Linux products, not future features.
Start here
- Getting started: sign in, select a workspace and connect.
- Install Forge Agent CLI on Windows or Linux.
- Access and enrollment: persistent devices, shared enrollment links, commands, transfers and history.
- Portable Rescue: attended temporary access and optional promotion to persistent access.
- Diagnostics: request only the evidence you need.
- Customers: companies, contacts and device relationships.
- Cases and drafts: record work, correct notes and review customer-facing text.
- Whisper status: bounded six-workspace production pilot, not general availability.
For automation, use the CLI reference and the curated HTTP API reference. For failures, start with troubleshooting.
What runs where
| Product | Purpose |
|---|---|
Forge Agent CLI (forge) |
Runs on the technician's Windows or Linux workstation. External agents use the same authorized commands as the technician. |
| Bridge | The website and API that own workspaces, authorization, device presence, customer context and history. |
| Forge Daemon | Persistent elevated service on an enrolled Windows or Linux device; reconnects after reboot. |
| Portable Forge Rescue | Attended, temporary elevated access, without installing the persistent service unless explicitly promoted. |
| Forge Diagnostics | A verified, one-shot collector run only after an explicit request. |
Connections use the native outbound HTTPS relay and public-key SSH/SFTP. The customer device needs no inbound LAN listener, support account, VPN client or Windows OpenSSH server. The technician needs OpenSSH client tools.
Workspaces and responsibility
In the current public service, human Admins and Technicians have ordinary workspace-wide device, history, customer and case access. Workspace settings, accounts, roles and invitations remain Admin-only. Switching workspaces never grants membership, and customer links or case assignments never grant access. Machine identities are a separate, explicitly scoped test capability—not a general unattended customer administrator.
One technician identity controls a device at a time; that identity may open several channels and work on several devices. Access is elevated. Agree the customer's scope before running commands or changing a machine.
Whisper is enabled only for six explicitly approved pilot workspaces. The old embedded OpenCode setup and disposable history are removed. Ordinary Forge Work/Cases and access through your own local agents remain available. No public general availability date is announced. Forge does not send customer email, provide a full CRM/PSA or guarantee recovery of every machine. See release applicability for the current boundary.