Scoped permissions
Read and action access follows the user’s account, workspace, role, and object context.
Use scoped roles, deny rules, expiring API keys, device controls, MFA, audit evidence and tenant-safe search across REST, AI and MCP surfaces.
Walk through this workflowWhy did fee income move this week?
The movement is concentrated in two receipt batches and one approved fee adjustment.
The workflow
Each stage carries its evidence and status forward, so the next person receives context instead of another handoff problem.
Start from the organization, workspace, period, people, and policies that govern the work.
Record the source event and evidence where it happens instead of recreating it downstream.
Keep the routine path fast while routing conflicts and incomplete evidence to a person.
Advance the workflow without erasing the earlier state, approval, or responsible actor.
The friction this removes
Controls that stay visible
Read and action access follows the user’s account, workspace, role, and object context.
Source records, comments, approvals, and reversals remain available after completion.
The interface, REST API, AI tools, and MCP use the same server-owned business rules.
The boundary
AI may
AI must not