Tenant and role isolation
Application commands derive workspace and live role from durable server state. Function-only grants, row policies, exact-version checks, and revocation tests fail closed across tenant boundaries.
Security · Implemented controls
Private data, credentials, approval, publication, billing, and provider effects are separated into reviewed trust zones.
Manifest senken-launch-quality-v1 · Founder approval required before public launchApplication commands derive workspace and live role from durable server state. Function-only grants, row policies, exact-version checks, and revocation tests fail closed across tenant boundaries.
Credentials are encrypted or one-way verified, scoped by runtime, and destroyed on revocation. Ambiguous external effects reconcile before retry so a timeout cannot silently duplicate a write.
The founder console reads content-free incidents and exposes closed canonical commands. It provides no raw SQL, generic tool, approval bypass, or customer-content mutation surface.