Security is the product
MemScope exists because sharing organizational memory is only useful if the boundaries hold. Access is computed, not negotiated.
Deterministic authorization
A single pure function, evaluate(), is the only thing that decides whether a memory may be read. It uses no AI and no database. The same inputs always produce the same decision.
AI never grants access
Classifier output is metadata. Governance can only tighten a deterministic ceiling — it can never widen access or override policy.
Admins manage, they don't read
Organization Owners and Admins manage people, teams and policy. There is no administrative bypass in the authorization engine — ever.
Platform staff see XXX
MemScope platform administrators cannot read customer memory content by default. Debug views return redacted content.
Time-limited support access
Customer-issued support grants last 1 hour, 24 hours or 7 days, are revocable, and every reveal is written to an append-only audit log.
Tenant isolation
Every query against tenant data filters by organization. Forbidden and missing records return the identical 404, so nothing leaks by inference.
Log redaction
Memory content never reaches logs. A central redaction layer turns raw content into XXX before it crosses a logging boundary, and exceptions never echo request bodies.
Immutable history
Raw memory content is immutable per version. Corrections create new versions; forget is a soft delete that authorized users can restore.
Separation of duties, by design
The person who runs the organization is not automatically the person who can read every memory. Platform operators are not exempt either. Support access is granted by the customer, scoped in time, and fully audited.
Review the API and MCP behaviorAccess decision
org_admin asks for memory content
│
▼
evaluate(principal, memory)
│
├── role = owner/admin → still needs a
│ data-access rule (no bypass)
│
└── platform_admin → content = XXX
unless active
customer grant