DOCUMENTATION / ALPHA

Security, identity and user authority

A capability system that supports cautious defaults without making user-configured power impossible.

Identity hierarchy

Root user identity signs device identities. Torsion Node and each browser profile have separate keys. Project memberships and endpoint credentials delegate defined authority and can be revoked independently.

Authority is visible

Policy decisions include deny, ask, allow-once, operation, session, project, peer, endpoint and always-allow. A user may create an unrestricted owner profile; the software records and displays that decision rather than silently replacing it with a narrower policy.

Security invariants

Power and safety are not opposites. The product must make consequences observable, authority inspectable and recovery reliable while retaining the user’s ability to authorize broad automation.