Skip to content
Ezra

Security

Security architecture.

Ezra treats identity, client boundaries, and approval scope as part of every request path.

  • Organization and client isolation

    Every record is bound to an organization and a client account identity.

  • Role-based channel access

    Requests resolve the requester's role and channel membership before work runs.

  • Encrypted connection credentials

    Provider tokens are stored encrypted and read only by the connection owner path.

  • Human approval for sensitive actions

    Consequential provider work waits for a named approver.

  • Durable audit history

    Requests, approvals, and outcomes are recorded with their evidence.

Architecture detail

Slack request verification
Inbound Slack requests are verified against the signing secret and timestamp before processing.
OAuth workspace binding
Each installation binds to one workspace identity, and work resolves against that binding.
Encrypted token storage
Provider tokens are encrypted at rest and read only through the connection owner path.
Organization and client isolation
Organizations, clients, connections, channels, artifacts, and actions carry durable identities.
Role and membership resolution
Requester role and channel membership are resolved for every request, not cached across clients.
Channel and client mapping
A channel maps to one client account. Unmapped channels receive no client data.
Connection and resource binding
Each connection is bound to the client and resource it was authorized for.
Provider action allowlists
Only allowlisted provider operations can be prepared, and each carries a parameter checksum.
Human approvals
Consequential work waits for a named approver with the scope recorded.
Feature flags
Capabilities can be enabled per organization while a release is being evaluated.
External-write kill switch
An organization can disable all outbound provider writes without removing Ezra from Slack.
Audit history
Requests, approvals, executions, and outcomes are recorded with their evidence references.
Revocation and uninstallation
Removing the Slack app or revoking a connection stops the associated work paths.
Data retention and deletion controls
Stored snapshots, artifacts, and memory records can be deleted on request where implemented.

Certification status

Security documentation reflects the current product architecture. Formal certifications will be listed only after completion.

Report a security issue

Send details to the security address configured for this deployment.

security@ezra.work

Give your agency another operator.