# Trust and scope: provenance, attribution and permission | Team0

> How Team0 separates support, provenance, relationship and attention, attributes views to their holders, and compiles the asker’s scope into every query: prevention, not redaction.

Agent-readable version of https://team0.ai/world-model/trust-and-scope. The page for people is at that address; this file carries the same content without layout.

---
# Trust and scope.

Two questions sit on every statement and every read: how much should this be believed, and who is allowed to see it. Team0 answers both structurally, in the data and in the query, rather than in instructions a model might not follow.

## Four questions, kept apart.

Most systems collapse everything into one relevance score. Team0 keeps four questions independent, because an answer to one never implies an answer to another.

Support
:   Is this a trusted belief, a piece of evidence, or still a candidate?

Provenance
:   Which exact message, meeting, calendar object or operation did it come from, and who said it?

Relationship
:   How does it connect to you: your contact, your customer, your family, a stranger?

Attention
:   Have you actually seen this exact item, or was it merely delivered to an inbox you own?

Why this matters

Receiving an email is not a relationship. Being in a group chat is not knowing someone. Attending a meeting is not agreeing to what was said in it. Keeping these questions apart is what stops a stranger’s “urgent” from jumping to the top of your day, and a third party’s opinion from being filed as your own preference.

## Whose view is it?

A statement has a subject and, for views, a holder.

A preference, opinion or recommendation records who holds it, and whether it is yours, someone else’s, or unclear. Your own settled preferences shape how Team0 understands you. Other people’s views stay attributed to them, and they are kept out of the picture Team0 forms of you, while plain facts from those same conversations still flow.

Things said by a connected agent carry that agent’s name, and are weighed as evidence. An agent cannot make its own words trusted, and it cannot correct your understanding on your behalf.

## Prevention, not redaction.

The common approach is to retrieve everything and ask the model not to repeat the private parts. Team0 never hands the model the private parts in the first place.

Every conversation starts by declaring who is on the other side. That declaration selects a scope, and the scope is compiled into the database query of every read. A public channel is answered from a public-scoped read: private statements are excluded before retrieval, so they never reach the model and there is nothing to leak.

The same rule protects the instructions a model sees. New context is dropped from any conversation with an outsider unless it explicitly declares that everyone may see it.

You
:   Your whole understanding and every tool.

A known contact
:   Coordination only, such as free and busy windows. Never access to what you know.

A cold email
:   Public knowledge about your business.

A website visitor
:   Public knowledge, a deliberately small set of abilities, and rate limits.

A meeting attendee
:   What is appropriate to say in that meeting.

Your connected agent
:   What its own grant allows, and nothing else.

Anyone undeclared
:   The most restrictive scope. Unknown callers fail closed.

## The rules.

1. 01

   Identity is declared, never inferred

   Who is asking is set where the conversation enters, never guessed from what they write.
2. 02

   Exposure defaults to the narrowest

   If anything about the caller is unknown, the most restrictive scope applies. Nothing fails open.
3. 03

   Reading is never permission to act

   Acting on your behalf needs a separate grant that names the operation, the exact recipient and the exact content.
4. 04

   One grant per agent

   Each connected agent has its own grant and credential. Revoking one kills its access and every live key, without touching the others.
5. 05

   Every read is on the record

   For connected agents, the exact request and the exact response are kept, so you can see what any agent worked from.
6. 06

   Emotional reads are never stored as facts

   Team0 can adjust its tone to a hard week. It never writes how you seem to feel into the graph.

## Compared with the usual approach.

|  | The usual approach | Team0 |
| --- | --- | --- |
| Private data | Retrieved, then the model is told not to reveal it | Excluded from the query before retrieval |
| Unknown caller | Often treated as the owner | Treated as the most restricted caller |
| Third-party opinions | Stored as memories about you | Attributed to their holder and kept out of your profile |
| Agent contributions | Written straight into memory | Named, weighed as evidence, never trusted automatically |
| Audit | Tool-call logs, if any | The exact request and response of every agent read |

- [OverviewThe World Model](https://team0.ai/world-model)
- [Data modelStatements, two clocks, belief lanes](https://team0.ai/world-model/data-model)
- [Entity resolutionOne person, one record, carefully](https://team0.ai/world-model/entity-resolution)
- [Truth maintenanceHow beliefs are retired, never deleted](https://team0.ai/world-model/truth-maintenance)
- [Understanding EngineFrom graph to a read an agent can use](https://team0.ai/world-model/understanding-engine)
- [Memory vs understandingWhat a memory layer does, and what understanding adds](https://team0.ai/memory-vs-understanding)
- [The 31 problemsEverything you have to solve, in one list](https://team0.ai/agentic-understanding)

## Your agents will change. Your understanding shouldn’t.

[What you control](https://team0.ai/trust)

Invite-only private beta.
