Security, permissions, and AI boundaries

Mekyro's trust model is not unlimited AI action. It is AI running automatically within clear authorization, policy gates, and data isolation.

Isolated workspace

Each customer's data, buyer-facing context, authorization settings, transaction records, and operating reports are isolated by default.

Permission boundary

The official site only describes entries. Real authorization is enforced by authenticated workspaces and backend permission rules; frontend menus are not security controls.

AI automation boundary

AI can prepare suggestions, run Skill workflows, organize Email, cite evidence, and move tasks; high-risk commitments require policy gates.

Sensitive data handling

Token, API keys, VM credentials, payment information, and private knowledge do not appear on the official site or public copy.

Human intervention boundary

Humans handle high-risk exceptions, authorization changes, and cooperation confirmation instead of turning daily operations back into manual queues.

What AI can do automatically

Low-risk actions

Organize leads, draft replies, update state, remind next steps, and compile knowledge.

Governed actions

Quotes, inventory, delivery commitments, payment, and refunds go through policy gates or human confirmation.

Forbidden actions

Read sensitive credentials without authorization, bypass permissions, fake payment results, or sign irreversible commitments for people.