Skip to main content

Applications

The Applications tab lists tools that other teams build on top of AI/Run CodeMie. CodeMie can list an application, embed it in the CodeMie page, or host it, and can give it corporate sign-in, AI models, and the CodeMie platform API. In return, applications shown inside CodeMie or hosted by it run regular security scans.

This page is for project and delivery managers. The engineering details are in the Integration Guide.

What CodeMie provides and what the application team provides​

CodeMie provides

A tile in the Applications tabApplication name and icon, visible to every CodeMie user
Corporate sign-inThe same login as CodeMie. Hosted applications need no extra login step
AI modelsGPT, Claude, and Gemini through one gateway, with per-user cost tracking and budgets
CodeMie platform APIAssistants, workflows, indexed project data, and existing Jira, Git, and Confluence connections
A place in CodeMie assistantsApplication features become tools that any CodeMie assistant can call
Hosting (by agreement)Cluster, CodeMie web address, certificates, secret store, database, and managed releases

Application team provides

A named ownerA product owner, a support contact, and an escalation path. Users report problems to CodeMie support first
Access controlThe application decides who can do what. CodeMie shows every tile to every user
Regular security scansCode, dependency, container, and web scans, with no open critical findings
An automated release pipelineBuilds come from a corporate repository, never copied by hand
Protected dataEncrypted, no personal data in logs, secrets kept only in a secret store
AI calls through CodeMieGuardrails, budgets, and cost reporting apply to every user

Three levels of integration​

Each level adds capabilities and adds requirements. Start at the lowest level that meets the need.

1

Linked

CodeMie
application
new tab

The tile opens the application in a new browser tab. The application runs wherever its team runs it.

Runs on
Application team infrastructure
Sign-in
The application's own corporate login
Effort
2

Embedded

CodeMie
application

The application appears inside the CodeMie page, so users never leave CodeMie.

Runs on
Application team infrastructure
Sign-in
Must work inside the CodeMie page, which often breaks on another domain
Effort
3

Hosted

codemie-host/your-app
application

The application runs in CodeMie's cluster under a CodeMie web address, embedded in the page.

Runs on
CodeMie's cluster
Sign-in
Automatic, shared with CodeMie
Effort
Plug-in variant

An application can also load as a component inside CodeMie's own page, running with the user's CodeMie session. This variant needs the highest trust and a code review by the corporate operations team before each release.

Connected at any level

At any level, an application can expose its features as tools that CodeMie assistants call. Users can then work with the application from a chat.

What each level gets​

Capability1 · Linked2 · Embedded3 · Hosted
Tile in the Applications tab✅ Yes✅ Yes✅ Yes
Corporate sign-in➖ The application runs the login➖ The application runs the login✅ Automatic
AI models through CodeMie✅ Yes✅ Yes✅ Yes
CodeMie platform API✅ From the application server✅ From the application server✅ From the application server
Tools inside CodeMie assistants✅ Yes✅ Yes✅ Yes
Web address under CodeMie❌ No❌ No✅ /your-app
Hosting, database, secrets❌ Application team❌ Application team✅ CodeMie cluster
Releases❌ Application team❌ Application team➖ The team's pipeline builds; the corporate operations team deploys

✅ provided by CodeMie · ➖ shared work · ❌ not provided

What CodeMie expects​

These requirements apply to embedded and hosted applications (levels 2 and 3). Scans run regularly, not only once before go-live.

Code scanSAST on every release
Dependency scanEvery release and weekly
Container scanTrivy on every image, every release and weekly
Web scanDAST against the running application, regularly
Secret scanOn every commit

Embedded and hosted

23
  • All scans above run on schedule, with reports shared with the corporate operations team
  • No open Critical or Urgent findings; fixes land before the next release
  • A named owner, support contact, and escalation path
  • Access control inside the application, because every user can see the tile
  • HTTPS and a stable web address
  • No passwords or keys in the tile settings, because every user can read them
  • Sign-in and every screen work inside the CodeMie page
  • The layout fits CodeMie: no second header, no broken styles
  • Plug-in variant: the corporate operations team reviews the code before each release

Hosted, in addition

3
  • Scans are built into the release pipeline, so an image cannot ship without them
  • Builds come from a corporate repository through an automated pipeline
  • No credentials in source code or container images
  • Secrets only in CodeMie's secret store; no personal data in logs
  • All AI calls go through CodeMie and are tied to the signed-in user
  • Every release is tested end to end before it reaches production

Do and don't​

Do

  • Use the shared sign-in, so users move from CodeMie to the application without a second login
  • Test every release before production and ship it through a reviewed change
  • Give the application team read-only access to its own logs and status
  • Expose application features as tools that assistants can use in chat
  • Keep a separate database per application, with passwordless cloud access

Don't

  • Ship container images from personal accounts or copy them by hand
  • Run a release pipeline with tests but no security scanning
  • Write access tokens or keys into source code
  • Use one shared AI key for all users, which hides who spends what
  • Ignore which user is signed in
  • Give every user power-user rights by default

Onboarding​

Purple steps apply to hosted applications only.

  1. 01Intake

    Purpose, owner, integration level, users, and the data the application touches.

    application team
  2. 02Access

    Sign-in client, CodeMie project, and AI model access.

    operations team
  3. 03Testing

    Deployed to a test environment and tested end to end.

    both
  4. 04Security review

    Embedded and hosted applications: scan reports and checklist reviewed against the requirements above.

    application team
  5. 05Go-live

    The tile is added and CodeMie is restarted. Hosted applications also deploy to production.

    operations team
  6. 06Run

    The application team handles incidents and releases, and every release repeats the scans.

    application team
note

Adding or changing a tile requires a CodeMie configuration change and a restart by the corporate operations team. There is no self-service screen, so agree on a date early.