WORLDIROpen console

Private by default

One tenant, one authorized evidence boundary.

WorldIR separates organization data in PostgreSQL row-level security and physical object and graph scopes. Agents cannot silently create a second write path.

Authentication

Magic links, passkeys, recovery codes and HttpOnly same-origin sessions.

Authorization

Role checks in handlers plus tenant-scoped database transactions.

Agent policy

Graph writes only through validated proposals; cited answers reject unsupported citations.

Privacy

No training on private files. Export and erasure are organization-controlled and audited.