Security

Security

What Workstate keeps apart, who can reach what, and how every change is attributed. This page describes what is built today, including what is not.

Namespaces keep things apart

Everything in Workstate lives in a namespace: its sources, its search index and its ledger. A search or a ledger entry in one namespace never reaches another.

Inside a namespace there are no per-document permissions. Everyone with access to it can search everything indexed in it. Put HR, legal and other restricted material in a namespace of its own.

Who can reach what

People sign in with GitHub, and only people who were invited can join an account. Each person has a role: Owner, Admin or Member.

Owners and admins choose which namespaces each person can reach, when they invite them and at any time after. Nobody can grant more than they hold, or change the access of someone above their own role.

Keys and attribution

Agents connect with a personal API key. It is shown once, when it is created, and can be revoked at any time. Workstate keeps only a digest of it.

Every ledger entry records the person whose key wrote it and the agent that sent it. Entries are never edited: a correction or a new decision is appended, and an outdated decision is superseded, not deleted.

Sources are read-only

The GitHub App asks for read access only and indexes the default branch of the repositories you share. Stop sharing a repository and it is removed from the index at the next sync.

Confluence and Jira are read with the credentials you give them, and uploaded files stay in the namespace you uploaded them to.

Not built yet

So that you can plan around them:

  • Single sign-on (SAML or OIDC). Sign-in is GitHub only.
  • Per-document permissions inside a namespace.
  • An exportable audit log.
  • Usage reporting.

Security questions, or something to report? Email hello@workstate.io. The details are in the security docs.

Give every agent the same memory

Workstate is in early access. Tell us about your team, and we’ll set you up.