TRUST / 02
Explicit boundaries for data, permissions, and action
Every workspace operates inside one organization scope. Connectors require explicit authorization before data is read or imported.
Organization isolation
Every read and write requires one tenant and organization context. There is no global customer-data query or cross-organization sharing.
Scope authorization
Preview data before import, select the permitted scope, and see the source state and permissions clearly.
Internal action by default
Agents read, analyze, and create internal tasks only. Messages and external mutations require a separate, explicitly authorized path.
Audit and metering
Runs, policy decisions, and evidence sources are recorded without storing secrets or full customer payloads in audit records.