Different from sharing your current screen
Delegated server access lets a prepared, enrolled agent open authorized terminal sessions to a selected destination. The agent holds an encrypted copy of the target credential and uses it for permitted access. This is a different trust arrangement from forwarding an encrypted view of your current live terminal.
The agent machine, its operator and its unlocked credential environment are trusted participants. Do not delegate a credential to an agent you do not control or trust.
Grant access deliberately
- Have the administrator prepare the enrolled agent and unlock its credential storage using the supported setup for that release.
- Open the sharing workflow and choose Server Access where offered.
- Verify the agent identity, destination, permissions and expiry. The invitation workflow asks you to approve an authenticated recipient; this is different from room-wide Live Share approval.
- Complete the credential and authorization prompts for the intended target.
- Wait for the agent to confirm installation of the grant; creating an invitation alone is not proof that access is ready.
- Test the recipient's actual permitted workflow before relying on unattended access.
Viewing an agent-owned terminal and controlling it are separate permissions. Only a control session should send terminal input or resize that terminal.
Keep the agent available
The agent must remain running, authorized and appropriately unlocked. A reboot or agent restart can require an operator to unlock credential storage again. Do not assume installing a background service gives it unattended access to locked credentials.
Loss of connectivity must not be treated as an extension of permission. Check both access status and agent readiness when a recipient cannot connect.
Remove access and confirm the outcome
Revoke the intended grant and check the reported result. When cutoff cannot be confirmed, investigate rather than treating a button press as proof of success. Stopping access does not erase material a recipient already copied or undo previously executed work.
Use Live Share for collaboration on your existing terminal. Read privacy and trust before choosing the delegated model for a sensitive server.