# Architecture & security

Constal limits authority with immutable identity, explicit boundaries, and least-privilege execution.

## Authority boundaries

| Concern | Guarantee |
| --- | --- |
| Agents and Channels | Execute one pinned immutable revision |
| Sessions and Runs | Preserve ordered work and durable history |
| Resources | Expose only declared operations allowed by Policy |
| Credentials | Remain encrypted and unavailable to Agent code |
| Analytics | Observe workflows without becoming workflow authority |
| Sandboxes | Isolate code and restrict external access |

## Security invariants

-   Agent and Channel code receives no ambient privileged storage, secret, analytics, or provider authority.
-   Identity is normalized before execution; Agent code sees only safe customer references.
-   Deployments, Policies, Resources, and Tools are pinned into Run authority.
-   Every external operation crosses authorization, durable recording, and effect-aware recovery.
-   Credential material is supplied only to the authorized integration that consumes it.

## Determinism and failure

Canonical hashes bind accepted definitions and inputs to exact semantics. Stale execution cannot change acknowledged truth. Direct nondeterminism and arbitrary network access are denied in managed execution; use journaled Resource operations. Stable SDK errors distinguish Policy failure, unknown outcome, lost execution, invalid binding, and related recovery cases.
