Skip to main content
An agent knowing a fact does not imply it may disclose that fact in every room. Subject affects relevance. Authenticated source evidence establishes provenance. The complete destination audience determines permission. A model cannot widen permissions by calling a fact harmless, relevant, or common knowledge.

Source audiences

Reader identities are opaque and namespace-scoped. Display names, the subject actor, people who have spoken in a thread, and deployment-global identity matches never grant access. Cross-connector continuity requires live proof for both accounts of the same sole reader and a verified direct destination. It never makes a private fact available to other people, groups, another workspace or another agent. Identity linking retains original audience snapshots and checks the proof graph when reading, including before final delivery. Explicit conversation restrictions remain in force; unknown evidence stays unavailable. Private evidence may enter a turn only when every possible recipient is in its permitted audience. A public thread still has its channel’s readership. A private Slack channel is private regardless of whether Mesh’s engagement gate calls its shape channel. Public Slack Connect channels have an open-ended external audience and remain unknown until that audience can be established. Slack audience snapshots are read from authenticated conversation information and complete membership pagination. Sources retain their observation-time snapshot. The runtime compares the persisted observation-time audience with the refreshed destination before a delayed turn, so even the trigger message cannot cross into an enlarged room, including after duplicate delivery. It checks again before sending its answer. Failure to verify the audience restricts context.

Revision and derivation rules

Every revision receives immutable source evidence in its canonical transaction. An amendment retains earlier evidence and adds its new source. A memory derived from other memories or loaded conversation history inherits all their evidence. The runtime conservatively tracks every remembered revision exposed during the turn, including explicit recalls; summarization cannot broaden access. No private material should be injected into a broader turn and then left to the model to redact. Trusted operator edits have no inbound message and retain the existing source audiences and conversation restrictions. They do not inherit sharing grants: an edited body requires fresh permission for any audience outside its original evidence. A source-less creation remains unknown until explicitly reviewed. Conversation-scoped legacy visibility remains an additional restriction. New source permissions apply even when a model requests perspective. Direct-ID amend/forget operations must satisfy the same read eligibility before a model can act on an entry. The conversation restriction survives derived summaries, even when the summary requests perspective. History retrieval requires audience evidence captured under this contract; legacy metadata cannot authenticate it. Agent replies carry protected memory_provenance references to the trigger, loaded history, and every memory revision exposed or written during that turn. message_source_evidence retains their original authors, audience snapshots, and conversation restrictions. Authorization-equivalent leaves are compacted to avoid multiplying the same private source with each reply; direct references remain in the event metadata. More than 5,000 distinct leaves becomes unknown, never a truncated permissive subset. An unproven bot reply also has unknown provenance. The bot is not an inferred owner who can approve someone else’s information. For example, Alex can approve a fact they supplied after several agent replies, but cannot approve Morgan’s private contribution copied through those replies. Amending or forgetting a memory does not remove its observed revision from the reply’s provenance. The final send check exempts revisions written or retired by that turn so the agent can acknowledge the mutation. Stored provenance retains the complete set of immutable revision IDs, including those exemptions, so a later summary still inherits their authors and audience restrictions. This lineage covers Mesh memory, messages, conversation history, and results from the remote MCP adapter. MCP results retain the operator-approved conversation and audience restrictions; their requester is not treated as the external data’s author. Legacy external tool sources still need their own access controls and provenance integration. Output must not be assumed public merely because a tool returned it. A release applies to one immutable revision and a specified audience. Private source attribution remains private when the released fact is rendered elsewhere. New text in a later revision needs new permission. Revocation is checked against canonical state, independently of whether external indexes have caught up.

Sensitivity and permission

Sensitivity assessment is advisory and optional. It may add a restriction or suggest asking the author about sharing. It cannot make private evidence public. Malformed responses and timeouts take the conservative path. The configured sensitivity classifier assesses remembered and amended bodies, with a two-second deadline. Its classification is retained in revision notes; sensitive or uncertain writes gain an additional conversation restriction. Disabling the advisor makes no extra model calls and does not weaken source-based permissions. For example, a personal travel plan learned in Alex’s DM is absent from public context, even when Alex asks about it in the public room. Naming Morgan in that plan does not authorize Morgan to retrieve it. An office event learned in a workspace-public room can be reused within that workspace. An announcement learned privately remains private until the author explicitly authorizes a defined audience, or independent public evidence supports a separately shareable claim. Sharing a claim never releases the original private transcript. Dreaming applies the same evidence rules to background learning and cleanup. A dream processes one audience at a time, inherits every exposed source, and cannot reuse a sharing grant for changed text without explicit review. Independent public-document extraction excludes its requesting DM. Privacy questions can be deferred to the original person’s next private turn; they never become background messages to a channel.

Operator boundary

The existing authenticated dashboard is a trusted deployment-administrator surface, not an actor login. Administrators retain access to canonical records and traces for review and recovery. These permissions govern what conversational agents may retrieve and disclose. Actor-bound operator roles and protection against the database operator require the separate access-control and encryption projects; do not represent the administrator dashboard as a private actor-facing portal.

Explicit sharing

In a verified single-counterpart private conversation, request_memory_sharing returns the exact current memory text, the proposed workspace/public audience, and an expiring code. The author confirms with share CODE in that same conversation within 15 minutes. Confirmation is parsed before inference and bound to the persisted actor, conversation, agent, and immutable revision. Someone else’s private contribution, an unknown source, an expired code, a different room, and a changed revision cannot be released by that confirmation. Replays do not create new grants. unshare CODE revokes a grant or cancels a pending request. The agent’s Memory page lets an authenticated operator inspect source evidence, review an exact revision, approve specific connector readers, a workspace, or public sharing, and revoke grants. The corresponding API is GET/POST /api/agents/{slug}/memory/{memoryID}/grants and DELETE /api/agents/{slug}/memory/{memoryID}/grants/{grantID}. POST requires the current revision and an explicit audience; an intervening edit returns 409. Private source/subject metadata is suppressed when only a sharing grant permits retrieval. Previously delivered messages, independently public observations, and other valid grants are not erased by revocation. Membership is rechecked before sending, but a connector cannot atomically couple its membership changes to Mesh’s database authorization and message send. As with any chat participant, a membership change after that check or later access to already-delivered channel history is governed by the chat service itself.