Identity Answers Who Is Acting
Every action in SpineWorkspace is identity-bound. No anonymous Work, no ambient capability access.Tenancy is the isolation boundary. Business Context Spine, projections, capabilities, and memory are all tenant-scoped. Cross-tenant access is a governance decision, not a default.
Identity Types
Twin identity derives from its human. Agent identity derives from the Work and the organizational role it represents.
Authority vs Permission vs Approval
- Authority — what this identity may do in this Business Context (derived from role + policy + Work context).
- Permission — the enforceable gate that checks authority at capability resolution time.
- Approval — a human or delegated authorization that satisfies a governance policy for a specific plan.
- Delegation — scoped, auditable grant of authority (e.g., “approve renewals under $X in this Work”).
Tenancy & Isolation
- One Spine per tenant. One projection per participant per Work.
- No capability or memory leaks across tenants. The operational sandbox is per-tenant and per-Work-context.
- Delegation never crosses tenant boundary without explicit governed action.
Where to Go Next
Governance & Authority
Policy → plan → approval → authorization — the verdict Hermes obeys.
Ecosystem & Integration
How each identity connects to ecosystems via One Auth scopes.
Security & Governance
Secrets, audit, provenance, isolation, fail-closed behavior.