DocumentationArchitecture
Permissions and trust
Authority comes from authenticated context and enforced grants, not from model instructions.
On this page
Four execution pathsNative permission boundariesData is not an instruction channelSecrets and identityExtension reviewThe personal agent chooses among the capabilities the platform exposes. The server and native adapters determine whether a requested action is allowed. Prompts and generated content do not grant authority.
Four execution paths#
| Path | Authority and execution |
|---|---|
| Server tool | Impo derives the owner from the durable invocation, checks arguments and dispatches through a server adapter. |
| Connected app | A server-verified connection selects one owned provider account. Provider credentials stay on the server. |
| Native tool | The attached installation advertises a capability. The server creates owned pending work; that installation claims, executes and reports it. |
| User-tapped action | The server prepares an owned action. A foreground user tap invokes the platform adapter. Preparing a card does not perform the action. |
Gadgets have a separate account-owned command path through the gateway, described in commands and events.
Native permission boundaries#
A conversation targets one registered phone. It does not inherit the union of capabilities from every phone the account owns. Dispatch rechecks the selected device's current capabilities.
OS authorization and application capability state are both relevant. Empty HealthKit data means unknown; it is not proof of denial or zero activity. Revocation blocks new execution. Previously accepted identical receipts remain idempotent.
Background work cannot assume a foreground phone. This is why ordinary Tasks do not receive native-device tools, and why Web does not claim HealthKit, contacts or background microphone access.
Data is not an instruction channel#
Tool output, connector content, device event payloads and command descriptions may contain untrusted text. Treat them as data. The dispatcher must enforce ownership and allowed operations regardless of what those fields ask the personal agent to do.
Model-facing schemas and runtime validation both matter. A schema helps the model produce an argument; the server must still validate the actual value received.
Secrets and identity#
Never ship Rebyte, Composio or speech-provider keys in a client or gadget. The server issues limited upload URLs and device setup credentials for their specific purpose. Gateway administration credentials are server-only.
Derive owner IDs from authentication or durable execution context. Do not accept a model-supplied userId as authority. Every conversation, task, file, recording and device request must re-establish ownership.
Extension review#
For each new capability, verify cross-account rejection, permission revocation, retry behavior, malformed input and account teardown. For native changes, add the OS permission and physical-device checks relevant to that capability.
The native tool contract, capability contract and security policy are the detailed references.