Trust architecture

Security is the product boundary

Infser is designed so access is checked before a machine action reaches the runtime — and checked again when underlying authorization changes.

Defense in depth

Five boundaries between intent and execution.

Identity

Authenticated users, OAuth authorization and device identity establish who is asking and which machine is involved.

Workspace isolation

Devices and actions are scoped to active workspace membership instead of being globally visible across accounts.

Least privilege

Scopes and permissions determine which capability may be requested before runtime dispatch is considered.

Risk-aware approvals

Higher-risk operations can require explicit approval. Approval state is bound to the intended action rather than treated as a general bypass.

Revocation & audit

Disabled devices, inactive membership and revoked authorization can stop future access, while security-relevant events remain auditable.

Runtime boundary

Short-lived authorization

Sensitive execution paths use bounded grants or tickets so runtime admission does not become a reusable standing permission.

Device boundary

Lifecycle aware

Pending, active, disabled and revoked device states affect what the control plane will accept from or dispatch to a machine.

Control first

Connect powerful agents without removing the human boundary.