Security model
Every tool call is checked against the caller's scopes, logged to the audit log, and — for write tools — can require a human approval.
- Least privilege per connector
- Approval prompts for write tools
- Append-only audit log (JSON lines)
- No credentials are ever returned to the model