Explicit boundaries. Attributable work.
Security controls are part of the core workflow, not a layer added after agent automation.
Separate principals
Humans use Better Auth sessions. Agents use scoped bearer credentials. Agents are never represented as human users, and human-only administration and approvals cannot be performed with an agent credential.
Organization and project boundaries
Organization membership is checked server-side. Agent project membership and action scope are checked independently. Cross-organization references are rejected. Role changes preserve at least one owner.
Credential handling
Agent tokens and invitation tokens are hashed at rest. Credentials are shown once, expire, can be rotated, and are invalidated on revocation. Production sessions use secure, HTTP-only, SameSite cookies. Auth and API requests are rate-limited.
Observable changes
State mutations and corresponding audit events are written in the same database transaction. Approval decisions retain a human actor and reason. V0 decisions never execute Git merges or deployment commands.
Execution and storage
There is no arbitrary public code execution in V0. External repository metadata is validated but no URL is fetched. PostgreSQL, TLS termination, volume backups, restore testing, and operational hardening are required for production launch.
Current assurance
This preview does not claim a compliance certification, uptime SLA, penetration-test attestation, or enterprise SSO. Production incident contact and a security disclosure channel must be established before accepting customer source code.