Trust boundaries

Identity, credentials, and authority across the Operator and end-user planes.

Identity model

An Operator is the workspace customer that builds and operates workflows. An Application is one deployed product boundary through which those workflows reach End Users. Staging and production are separate Applications.

An External Subject is Linea's canonical representation of an End User within a workspace and identity issuer. It is not a Linea account or workspace member.

Credential boundaries

CredentialCanCannot
Member sessionPerform actions allowed by the workspace roleAct as an external End User
Workspace KeyUse explicitly granted workspace operationsSubstitute for an Application Key or End-User Session
Application KeyAccess one Application's server-side runtime resourcesCross Applications or change identity trust configuration
End-User SessionAct within its subject, Application, audience, and scopesAdminister the workspace or act for another subject

Data boundary

Repositories accept workspace identity as part of their query contract. Where a child identifier could be guessed or replayed, composite ownership constraints prevent it from escaping the parent workspace or Application.

Never move secrets into the client

Application Keys, Workspace Keys, provider credentials, and connector refresh tokens remain server-side. A browser receives only the narrow End-User Session capability intended for that boundary.

On this page