ReasonTrail for Teams is now available

Security

Access is scoped before context is assembled.

This page describes implemented product boundaries and operating practices without claiming certifications or guarantees that have not been documented.

01

Authentication

Server-side sessions protect browser routes. Invited or existing users may sign in with Microsoft Entra ID. ReasonTrail invitations and membership — not Microsoft tenant membership — control organization access. Mutations use CSRF protection, and accounts or organizations can be suspended.

02

Tenant isolation

Private queries are scoped by owner and organization. MCP validates the active organization, project access and token restrictions server-side. Raw conversations stay owner-private while approved project knowledge can be shared.

03

Provider boundary

Only selected context is sent. Provider keys remain server-side; models do not receive database credentials.

04

Review + authorization

Important proposals remain reviewable. Sensitive Operator approvals are scoped to a single owner and run.

Restricted capabilities

Models do not receive unrestricted system access.

× No unrestricted shell access× No unrestricted filesystem access× No arbitrary repository mutation× No deployment access× No browser automation access× No credentials or database connections

Data operations

Inspectable records and bounded logs.

ReasonTrail preserves failed runs, verification evidence, approvals, and audit history for diagnosis.

PostgreSQL storageBackupsJSON exportsMarkdown exportsAudit eventsBounded, redacted logs