Applications
The Applications tab lists tools that other teams build on top of AI/Run CodeMie. CodeMie can list an application, embed it in the CodeMie page, or host it, and can give it corporate sign-in, AI models, and the CodeMie platform API. In return, applications shown inside CodeMie or hosted by it run regular security scans.
This page is for project and delivery managers. The engineering details are in the Integration Guide.
What CodeMie provides and what the application team provides
CodeMie provides
Application team provides
Three levels of integration
Each level adds capabilities and adds requirements. Start at the lowest level that meets the need.
Linked
new tab
The tile opens the application in a new browser tab. The application runs wherever its team runs it.
- Runs on
- Application team infrastructure
- Sign-in
- The application's own corporate login
- Effort
Embedded
The application appears inside the CodeMie page, so users never leave CodeMie.
- Runs on
- Application team infrastructure
- Sign-in
- Must work inside the CodeMie page, which often breaks on another domain
- Effort
Hosted
The application runs in CodeMie's cluster under a CodeMie web address, embedded in the page.
- Runs on
- CodeMie's cluster
- Sign-in
- Automatic, shared with CodeMie
- Effort
An application can also load as a component inside CodeMie's own page, running with the user's CodeMie session. This variant needs the highest trust and a code review by the corporate operations team before each release.
At any level, an application can expose its features as tools that CodeMie assistants call. Users can then work with the application from a chat.
What each level gets
| Capability | 1 · Linked | 2 · Embedded | 3 · Hosted |
|---|---|---|---|
| Tile in the Applications tab | ✅ Yes | ✅ Yes | ✅ Yes |
| Corporate sign-in | ➖ The application runs the login | ➖ The application runs the login | ✅ Automatic |
| AI models through CodeMie | ✅ Yes | ✅ Yes | ✅ Yes |
| CodeMie platform API | ✅ From the application server | ✅ From the application server | ✅ From the application server |
| Tools inside CodeMie assistants | ✅ Yes | ✅ Yes | ✅ Yes |
| Web address under CodeMie | ❌ No | ❌ No | ✅ /your-app |
| Hosting, database, secrets | ❌ Application team | ❌ Application team | ✅ CodeMie cluster |
| Releases | ❌ Application team | ❌ Application team | ➖ The team's pipeline builds; the corporate operations team deploys |
✅ provided by CodeMie · ➖ shared work · ❌ not provided
What CodeMie expects
These requirements apply to embedded and hosted applications (levels 2 and 3). Scans run regularly, not only once before go-live.
Embedded and hosted
- All scans above run on schedule, with reports shared with the corporate operations team
- No open Critical or Urgent findings; fixes land before the next release
- A named owner, support contact, and escalation path
- Access control inside the application, because every user can see the tile
- HTTPS and a stable web address
- No passwords or keys in the tile settings, because every user can read them
- Sign-in and every screen work inside the CodeMie page
- The layout fits CodeMie: no second header, no broken styles
- Plug-in variant: the corporate operations team reviews the code before each release
Hosted, in addition
- Scans are built into the release pipeline, so an image cannot ship without them
- Builds come from a corporate repository through an automated pipeline
- No credentials in source code or container images
- Secrets only in CodeMie's secret store; no personal data in logs
- All AI calls go through CodeMie and are tied to the signed-in user
- Every release is tested end to end before it reaches production
Do and don't
Do
- Use the shared sign-in, so users move from CodeMie to the application without a second login
- Test every release before production and ship it through a reviewed change
- Give the application team read-only access to its own logs and status
- Expose application features as tools that assistants can use in chat
- Keep a separate database per application, with passwordless cloud access
Don't
- Ship container images from personal accounts or copy them by hand
- Run a release pipeline with tests but no security scanning
- Write access tokens or keys into source code
- Use one shared AI key for all users, which hides who spends what
- Ignore which user is signed in
- Give every user power-user rights by default
Onboarding
Purple steps apply to hosted applications only.
- 01Intake
Purpose, owner, integration level, users, and the data the application touches.
application team - 02Access
Sign-in client, CodeMie project, and AI model access.
operations team - 03Testing
Deployed to a test environment and tested end to end.
both - 04Security review
Embedded and hosted applications: scan reports and checklist reviewed against the requirements above.
application team - 05Go-live
The tile is added and CodeMie is restarted. Hosted applications also deploy to production.
operations team - 06Run
The application team handles incidents and releases, and every release repeats the scans.
application team
Adding or changing a tile requires a CodeMie configuration change and a restart by the corporate operations team. There is no self-service screen, so agree on a date early.