How are organizations isolated?
Every read, write, search, collaboration record, notification, import, export, and storage lookup is scoped to one organization. Handover does not use a client-supplied organization ID as proof of access.
How are people authenticated?
Production web access uses Google SSO through Cloudflare Access. The signed identity is resolved to an organization membership, invitation, or approved-domain join policy before company context becomes available.
How are agents authenticated?
Agents use revocable credentials tied to a named service identity. Secret values are shown once, stored only as hashes, and limited by explicit organization and read or write scopes.
When is context public?
Context becomes public only through an explicit publication action. Mentions, assignments, folder placement, and provider exports do not make a restricted handover public.
FAQ
Frequently asked questions
Can mentioning someone grant them access?
No. Mention candidates must already be authorized and notifications recheck current access before appearing.
Can external viewers write through MCP?
No. Collaboration and revision writes require an identity with the necessary write scope; read access alone is insufficient.