One connection · Explicit access

One lean AI connection. Shaped around the work.

SPORT keeps the model-facing tool surface small. Behind it, we’re building a setup path that turns projects, team roles, provider connections, and reference bundles into the access each person and agent can actually use.

Talk with Tim about early accessInvite-only. No public signup.
Target workflow · In build

Access resolved for this project

Preview
ProjectTim Wolf Brand
MemberMaya Chen
Assigned roleContent Operator
Effective access
Tools12 approved tools
ConnectionsPersonal GWS · Shared Granola read
KnowledgeBrand Core v4 · Content Playbook v2
PolicyRead + draft · Approval required to publish

Role permissions combine with live membership, project bindings, provider scope, and platform policy. Default deny still wins.

Set the boundary once

Build access from the project outward.

SPORT turns account setup into an explicit chain. Each step narrows what the next step can expose.

  1. 01 · Projects

    Define the work boundary

    Create the internal or client project that will own connections, references, usage, and evidence.

  2. 02 · Team

    Add people and agents

    Membership establishes who may enter the workspace and which projects they can reach.

  3. 03 · Roles & Access

    Assign responsibility

    Use a role template, custom role, or narrow direct grant. The assignment describes allowed operations; it carries no credential.

  4. 04 · Connections / OAuth

    Bind the provider identity

    Connect personal OAuth or deliberately shared provider access, then bind it to the right project and resource scope.

  5. 05 · Tools + References

    Let SPORT resolve access

    The assigned role now yields only the tools, connections, and reference bundles allowed by every live boundary.

Assign once · Resolve live

A role becomes governed working access.

The owner assigns Content Operator to Maya inside Tim Wolf Brand. SPORT intersects that role with the project’s active connections, reference bindings, provider scopes, direct grants or denials, and current policy.

Role assignment
Content Operator → Maya Chen → Tim Wolf Brand
Effective access
Tools · research, draft, document search
Connections · own Google identity + delegated Granola read
Knowledge · project-bound brand and content bundles
Denied · publish, credential changes, other projects

Changing the role, membership, binding, or provider scope changes effective access. No model-selected fallback account.

The model sees four routers

The control plane resolves the rest.

The production foundation keeps tool discovery behind four code-owned router tools. The planned trust kernel resolves actor, project, role, connection, reference scope, and current policy before a selected capability runs.

Model-facing surface
01search_tools
02describe_tools
03call_tool
04get_task
Server-side resolution
IdentityActor + client
BoundaryWorkspace + project
PermissionRole + direct grants
ProviderConnection + scope
KnowledgeBundle + version
DecisionPolicy + approval

Finding a capability is not permission to run it. Authorization is checked again at execution.

Live

Fixed four-router entry point, on-demand catalog discovery, execution authorization, queued work, and usage attribution.

In build

Multi-workspace identity, projects, roles, governed personal and shared connections, and exact reference bundles.

Later · Eval-gated

Semantic retrieval follows exact citations, freshness, isolation, and corpus-specific quality and cost tests.

Early-access conversation

Bring one project and one boundary worth proving.

We’re working with a small group of AI-friendly teams and agencies that can test real tools, connections, and Markdown knowledge with honest feedback.

Talk with Tim about early accessA conversation first. No automated onboarding.