Private content requires an authenticated user, across the shared IOA user base.
Give rich agent work
a controlled destination.
Upload a self-contained HTML artifact—or let an agent publish it—and receive a durable review URL. Every artifact starts behind IOA’s WorkOS sign-in; external access is explicit, revocable, and temporary.
station publish ./artifact.html→private URLUploaded code runs in an opaque, network-disabled sandbox away from application data.
Public URLs are unlisted bearer links with mandatory expiry and immediate revocation.