Understand Minds
GUIDE & REFERENCE

Authority and data boundaries

Know who is calling, which data they can access, and what they can do.

Minds has more than one security boundary. A signed-in user manages an organization. An application connects to an instance. A capability limits what a request may do within a namespace. Some engine controls require separate operator authority.

Match the credential to the interface

Credential or authorityIntended boundary
Browser sessionSigned-in Minds platform workflow
Platform authorizationAccount and organization management
Signed instance capabilityNamespace and action authority inside Akasha
Operator credentialRestricted engine administration
Optional legacy JWTAdditional deployment-specific authentication

Use the platform authentication and instance authentication pages for the exact transport requirements. A key generated by a demo wizard is not an issued credential.

Isolation has several layers

Dedicated Firecracker VMs are the required runtime boundary for Free and Pro. Namespace authority restricts data access within an instance. Learning isolation controls acceptance of information. These layers complement each other; none replaces the others.

Verify secondary transports

The source audit found missing or incomplete authority enforcement around gRPC and Arrow Flight. Keep these listeners private unless the deployed transport and network controls have been verified. The HTTP reference's capability contract does not automatically apply to another protocol.

Protocol boundaries · Current compatibility

On this page