Feature libraryUpdated 2026-09-14

Govern and query the Catalog

Planned for Phase 1

Every artifact will receive a determined access level before it becomes queryable. Provenance sets the broadest level the system may assign, the typology may narrow it, and an administrator may make a logged, reversible override.

The automatic rules never widen access beyond the provenance ceiling. A channel involving a customer, for example, cannot automatically produce an internal-only default. An unknown party leaves the ceiling unresolved, so the artifact waits for an administrator instead of becoming queryable.

Whole records, filtered audiences

Governance controls which artifacts a caller receives. An authorized artifact is returned whole, exactly as extracted; an unauthorized artifact is absent from the result. Provenience does not redact or trim part of an artifact to fit an audience.

MCP access

The planned MCP server will let an authorized user ask natural-language questions from clients such as Claude or ChatGPT. Results come from structured Catalog artifacts, include citations to raw sources, and are logged with the query.

Phase 1 has one internal administrative role. Customer-facing and staff-scoped roles are deferred. OAuth-backed MCP access and tenant-bound query enforcement are part of the design contract, not currently available features.

Capabilities covered

This page covers C11 and C12 in the Phase 1 design contract.