HHandover
All documentation

Security

How Handover protects shared context

Understand tenant isolation, Google SSO, service identities, scoped credentials, restricted handovers, and deliberate public publishing.

How are organizations isolated?

Every read, write, search, collaboration record, notification, import, export, and storage lookup is scoped to one organization. Handover does not use a client-supplied organization ID as proof of access.

How are people authenticated?

Production web access uses Google SSO through Cloudflare Access. The signed identity is resolved to an organization membership, invitation, or approved-domain join policy before company context becomes available.

How are agents authenticated?

Agents use revocable credentials tied to a named service identity. Secret values are shown once, stored only as hashes, and limited by explicit organization and read or write scopes.

When is context public?

Context becomes public only through an explicit publication action. Mentions, assignments, folder placement, and provider exports do not make a restricted handover public.

FAQ

Frequently asked questions

Can mentioning someone grant them access?

No. Mention candidates must already be authorized and notifications recheck current access before appearing.

Can external viewers write through MCP?

No. Collaboration and revision writes require an identity with the necessary write scope; read access alone is insufficient.