Identity, authority & proof
Security controls follow the actor, runtime, capability, and action.
Human and organization identity define the operating boundary. Agent and runtime identity identify the performer inside it. Delegated scope, capability classification, policy, and approval determine whether a requested effect may cross that boundary, while receipts and evidence retain an attributable record.
Bounded delegation
Work passed between agents retains its requester and causal path. Delegation narrows a task; the receiving runtime still needs valid capability authority and any required approval.
Runtime isolation
Independent runtimes own separate identity, model assignment, task and event state, context scope, capability authority, lifecycle, and Companion projection under shared governance.
Tenant and resource scope
Organization, user, runtime, environment, connector, and exact target boundaries prevent authority from becoming a broad credential shared across unrelated work.
Credential boundary
Connectors resolve credentials at the execution boundary. Models, generated applications, and collaboration messages receive permitted results rather than raw stored secrets.
Cryptographic verification
Current governance receipts are signed and verified with Ed25519, retaining available actor, request, action-lineage, evidence, artifact, timestamp, and integrity references.
Administration and retention
Administrative controls govern membership, roles, providers, connectors, approvals, revocation, evidence access, and the configured retention path without exposing private control mechanics.