BuildWithHQ
Canonical knowledge unit · security

Security invariants

Security is designed as a shared structural layer: server-derived identity, one authorization path, explicit tenant/application/location scope, and separate permissions for read, AI, export, and sensitive disclosure.

ID: BWHQ-SEC-001Status: currentAuthority: highestsecurityauthorizationidentitypermissions

Security invariants

Invariants

Service boundary

Browser-facing identities should execute safe procedures/API contracts and should not receive privileged provisioning/billing identities or direct unrestricted table DML.

AI implication

An AI tool or MCP adapter inherits the same permission envelope. Tool discovery and retrieved context should be narrowed by authorization before the model acts.

Machine-readable source: canonical Markdown. This HTML companion exists for human reading, search indexing, and AI retrieval.