Access resolved for this project
Role permissions combine with live membership, project bindings, provider scope, and platform policy. Default deny still wins.
SPORT keeps the model-facing tool surface small. Behind it, we’re building a setup path that turns projects, team roles, provider connections, and reference bundles into the access each person and agent can actually use.
Role permissions combine with live membership, project bindings, provider scope, and platform policy. Default deny still wins.
SPORT turns account setup into an explicit chain. Each step narrows what the next step can expose.
Create the internal or client project that will own connections, references, usage, and evidence.
Membership establishes who may enter the workspace and which projects they can reach.
Use a role template, custom role, or narrow direct grant. The assignment describes allowed operations; it carries no credential.
Connect personal OAuth or deliberately shared provider access, then bind it to the right project and resource scope.
The assigned role now yields only the tools, connections, and reference bundles allowed by every live boundary.
The owner assigns Content Operator to Maya inside Tim Wolf Brand. SPORT intersects that role with the project’s active connections, reference bindings, provider scopes, direct grants or denials, and current policy.
Content Operator → Maya Chen → Tim Wolf BrandChanging the role, membership, binding, or provider scope changes effective access. No model-selected fallback account.
The production foundation keeps tool discovery behind four code-owned router tools. The planned trust kernel resolves actor, project, role, connection, reference scope, and current policy before a selected capability runs.
search_toolsdescribe_toolscall_toolget_taskFinding a capability is not permission to run it. Authorization is checked again at execution.
Fixed four-router entry point, on-demand catalog discovery, execution authorization, queued work, and usage attribution.
Multi-workspace identity, projects, roles, governed personal and shared connections, and exact reference bundles.
Semantic retrieval follows exact citations, freshness, isolation, and corpus-specific quality and cost tests.
We’re working with a small group of AI-friendly teams and agencies that can test real tools, connections, and Markdown knowledge with honest feedback.