Tenant isolation
Authenticated deterministic code establishes tenant scope and permissions. Model output cannot change authorisation or cross a tenant predicate.
Smoozen security and trust
Smoozen uses deterministic tenant and role controls, bounded data contracts, redacted observability, signed callbacks, and explicit rollback paths.
Trust architecture
Each control answers a practical question: who may act, what may cross the boundary, and where the authoritative decision belongs.
Authenticated deterministic code establishes tenant scope and permissions. Model output cannot change authorisation or cross a tenant predicate.
The client remains authoritative for identity, consent, bookings, payments, safety, and final user-facing records.
Stale data, connector failures, invalid callbacks, telemetry failures, and unavailable providers fail closed or route to manual fallback.
Capabilities receive only approved fields. Secrets, payment details, identity documents, and unrestricted records are excluded by default.
Sensitive actions use bounded sessions, correlation identifiers, append-only audit expectations, and explicit rollback boundaries.
The owner-only break-glass path is visibly separate, time-bound, email-code protected, and still cannot bypass RLS, consent, safety, audit, or client authority.
Evidence maturity
A bounded control is represented in the current Preview interface and contracts.
Manual, security, privacy, accessibility, failure, and rollback evidence still needs its approved verification window.
Owner approval and the public launch gate remain separate from a successful build or automated test run.
Security review, penetration testing, privacy and legal approvals, manual verification, monitoring evidence, and rollback readiness remain required before production operational enablement.