Scoped access

Agents see only what they should.

An agent working a hiring approval needs the headcount plan and the budget envelope. It does not need anyone’s performance review. Annex draws that line on your org chart and enforces it in code.

Access is a path, not a setting

Every agent sits somewhere in your organisation — say acme/finance/budget-team/budget-checker. It can read context filed at its own path or any path above it, so it sees company-wide facts and finance-wide facts, but nothing filed under acme/hr. HR is a sibling, not an ancestor.

Matching is on whole path segments, so acme/finance grants nothing at acme/finance-ops. Try it below — switch agents and watch what drops out of view.

reading asacme/finance/budget-team/budget-checker
  • acmeQ3 headcount plan approved — 4 eng, 1 ops.org
  • acme/financeEngineering envelope: $1.2M remaining.dept
  • acme/peopleComp review cycle opens Sep 15.out of scope
  • acme/people/hiringBackend req approved at L5 band.out of scope
  • acme/ops/itLaptop lead time is 9 days.out of scope
2 of 5 memories visible to Finance — the rest are siblings, not ancestors.

Why this matters more than the context itself

Handing agents a big pile of company context is easy. The hard part — and the part that decides whether Finance will let an agent near their numbers — is being able to say exactly what it could and couldn’t see, and prove it afterwards.

So the boundary is the product. Every read runs through it, every refusal is recorded, and the answer to “could it have seen that?” is a lookup rather than an opinion.

Boundaries follow the org chart

An agent reads at its own level and above. Siblings are invisible to each other.

Deliberate sharing

Facts are filed company-wide, department-wide, or team-only. You choose which, per agent.

Whole-segment matching

acme/finance grants nothing at acme/finance-ops. Different department, different branch.

Stored as written

Context isn't re-summarised by a model between teams. What Finance filed is what People reads.

See it on your own org chart.