Access & governance

Control is built into how the system works.

Every step — from setup to usage — follows a defined structure. Access is limited. Actions are contained.

Nothing operates outside the flow.

Control comes from how the system is structured

Every action lives inside a clear, natural flow. Nothing is free‑floating.

Template
Project
Pipeline
Team
Usage

Control comes from structure, not restrictions.
Each step naturally limits what comes next. A template defines the shape of a project. A project contains pipelines. Pipelines move data only where allowed. Teams are assigned to specific work. Usage stays inside these walls.

who can access

Access is tied to projects

You don't get access to everything at once. Each person belongs to specific teams, and each team is assigned to a project.

A team working on one project cannot see or change another project unless explicitly added. There is no “global access” across the system.

Different levels of responsibility exist, but always inside a project boundary.

Project‑based access

Team members see only what belongs to their assigned project.

No accidental exposure

Data, pipelines, and settings from one project stay completely separate.

Full visibility of boundaries

You always know exactly what you can and cannot access.

what can be done

Actions are always limited

Every operation is constrained by role and context. No unrestricted “god mode”.

Changes happen inside defined scope

You can only edit resources that belong to your project and pipeline.

No unrestricted operations

Deleting, moving, or modifying data requires explicit permission.

where data moves

Pipelines define data flow

Pipelines are the only paths data can travel. Data does not jump across pipelines without being explicitly connected.

Each project maintains strict separation – data from Project A never mixes with Project B unless you build a visible, controlled bridge.

Data moves exactly where you define, never freely or invisibly.

Project: Payments
pipeline: authorize→ card data
can read from vault, cannot write to logs
pipeline: settle
only sees authorized transactions
No invisible access
external guidance

Signals are controlled inputs

You can add signals to guide system behavior — but they never override the underlying structure.

Operate within boundaries

A signal can suggest, not bypass access rules.

Visible and auditable

Every signal is attached to a specific pipeline or project.

Do not override structure

The system's containment remains absolute.

Nothing operates without structure

Access

is defined

Actions

are limited

Data

is contained

This is not added later. It is built into how the system works.

Looking for the technical specifics?

See the Security Specifications page for authentication, encryption, and access control details.

Explore how this applies to your setup

See the actual flow, project boundaries, and team assignments for your own use case.