Tenant isolation
Client records, mappings, users, thresholds, endpoints, credentials and model artifacts remain inside the approved tenant boundary.
Client data is isolated, authority is explicit and every model output, approval and external action can be traced to the version and evidence that produced it.
Client records, mappings, users, thresholds, endpoints, credentials and model artifacts remain inside the approved tenant boundary.
Authentication, authorisation, approval boundaries and side-effect permissions are enforced at the service and adapter boundaries.
Source authority, provenance, freshness, conflicts and classification travel with evidence through the decision path.
Decisions, model versions, approvals, intents, completions and outcomes retain replayable lineage.
| Reusable software | Versioned engine code and contracts remain separate from client records and configuration. |
| Client environment | Contains source connections, identity mappings, roles, permissions, approved model artifacts and deployment settings. |
| External actions | Every permitted write requires a named adapter, permission, approval rule and duplicate-prevention contract. |
| Models | Artifacts are versioned, scoped, monitored and expired explicitly, with a declared fallback. |
Bring the hosting, access, integration and procurement requirements that govern the decision and its data.
Discuss the decision