An agent that can read a schema can be asked to drop a table. The question for an enterprise is not whether the model is clever but what the platform lets it reach, under whose identity, and what is written down afterwards. This is the model as it runs today, in five parts, each of which shipped as code over the last two months.
Four worlds
- The URL declares intent A session opens on one endpoint: development, scoped to a dictionary; application, scoped to a data database; administration, on a fixed path for administrators; and the unscoped workspace door, which is being retired. The endpoint decides which providers exist at all.
- Absent, not refused A provider declares the worlds it serves, and the registry never consults it outside them. Administration tools are not hidden from a development session; they do not exist there, and a test asserts it from the declarations.
- A session belongs to its door A session id minted for one endpoint is unknown to the others, and a stored session is served only to the user who opened it.
- The caller is themselves The caller is resolved on their own rows. A delegation to act as another user never reaches an agent.
Four risk classes
- R0 to R3 R0 reads: nothing it does needs undoing. R1 writes: recoverable, because journalled, restorable or trivially redone. R2 is security-sensitive: credentials, roles, grants, blocks, and what a whole fleet resolves through. R3 is destructive: irreversible, or reversible only from a backup someone has to find.
- Declared in code Every tool carries its category and its class, and the build fails on a tool that declares neither.
- A ceiling per database A user's grant on a database names the highest class an agent may reach there, or none at all. Above R0 the grant must hold insert, update and delete together: a partial writer is a reader.
- A grant chooses, a role opens The role gate is a floor a grant cannot lift. A grant selects among the tools a role already opens, by tool, by pattern or by whole category, with a note required and each tool's dependencies added.
- Dry by default A write previews first. The plan comes back, and for a record the row diff, before anything runs.
Five gates, run again on the call
- In order The world decides which providers exist; the entry decides who may open it; roles decide which families are on the table; the allowance decides which tools inside them; and every gate runs again on the call, with the environment: production is refused to development tools unless a named privilege lifts it.
- Listing hides, the call enforces A tool the user may not use is left out of the list, because a name is a disclosure, and the server log says how many were hidden and why. A name a client sends anyway meets the same gates.
- Refusals carry a kind Ten kinds, from a missing argument to a failed proof. Every refusal site is classified, one live refusal per kind is under test, and a sweep counts an unclassified refusal as a fault.
One audit
- Every call, one row Who, from where, in which world and target, the order of the call in its session, the bytes and tokens in both directions, and the outcome: ok, refused, gated, error or cancelled. A refusal is recorded as a failure, never as a success.
- The commands behind the call One row per statement a call sent to an engine, with the text, secrets masked, the time it took and the error if any. A delete journals a backup row for every row it removes.
- Secrets never land Arguments are redacted before the row is written.
- Who reads it A user reads their own session report with no administrator role. Administrators list, read and aggregate across users. Purging the audit is itself an R3 tool.
The changeset journal
- In the same transaction A write is journalled with its before and after images as it commits. A write with no effect journals nothing. A code write shares size, checksum and delta with a save from the editor.
- Deletes keep the body A deleted routine or object keeps its body as the before-image, and a restore plan stays a plan until someone acts on it.
- Bound to the session Changes group into waves per MCP session, a wave bound to another session is never joined, and the audit joins to the journal on the session id. The version note carries the agent's own comment, marked as made over MCP.
As of this week the catalogue holds some 240 tools, 143 of them read-only and 21 destructive. A development session lists 144 of them under a 50,000-token ceiling, an administration session 94. The counts move with every release. The five parts do not.