Source permissions and security
Sentium applies least privilege at the provider, tenant, source, processing, and Agent boundaries. A successful provider authorization is necessary, but it is never sufficient by itself to make content available everywhere.
Provider boundary
Connections are limited to the folders or repositories selected by an authorized user. Provider administrators retain their own application approval, account, and access controls. Sentium does not instruct customers to bypass those controls.
Provider credentials are encrypted and never enter Agent prompts or tenant-agent runtimes. Customers should never paste access tokens, authorization codes, secrets, or private keys into Sentium fields or support messages.
Tenant and scope boundary
Every connection is tenant-bound and mapped to an exact company or device scope. Tenant isolation, workspace membership, role permissions, and source eligibility are enforced before retrieval. Company scope does not cross tenant boundaries; device scope does not silently expand to other devices.
Processing boundary
Source bytes are scanned before parsing. Parsers do not execute macros, archives, or embedded code. Unsupported, unsafe, encrypted, or malformed files fail closed with a visible status.
Evidence boundary
Extracted material retains source-version provenance. Inferred relationships remain labeled as inferred and cannot become controlled evidence without review. Agent responses and drafts retrieve only processed, authorized Sentium versions; they do not receive provider credentials and do not live-read provider files.
Follow how source connections work for the complete authorization model and source data lifecycle for retention and deletion.