SGM defines the boundaries an implementation must enforce, while leaving the mechanism implementation-specific. This document covers sensitivity metadata, authorization boundaries, and licensing.

Sensitivity metadata

A record MAY carry a sensitivity object declaring how it should be handled:

"sensitivity": {
  "level": "confidential",
  "contains_secrets": false,
  "pii": true
}
Field Type Meaning
level enum public | internal | confidential | restricted
contains_secrets boolean Whether the content includes credentials/keys
pii boolean Whether the content includes personal data

An implementation SHOULD surface sensitivity to consumers and MUST round-trip it losslessly. An implementation that detects contains_secrets: true SHOULD warn on export but MUST NOT silently drop the field.

Authorization boundaries

The protocol requires that a boundary exists and is enforced around every operation, even though the auth mechanism is implementation-specific:

  1. Every operation runs within a scope (see scopes.md).
  2. Cross-scope access MUST be explicitly authorized, never implicit.
  3. An unauthorized cross-scope attempt MUST return scope_denied, never a silent empty result.
  4. An implementation with no authentication MUST treat every scope as private to its own process — no cross-process/cross-user leakage.

SGM does not mandate OAuth, API keys, mTLS, or any specific scheme. It mandates that some boundary is enforced.

Secrets hygiene

Provenance as a security control

Provenance (see provenance.md) is a security feature: because every record identifies its creator, session, and origin, a consumer can judge trustworthiness and detect records from unexpected agents. An implementation MUST preserve provenance unmodified — tampering with it would defeat this.

Licensing

SGM is released under the GNU Affero General Public License v3.0 (LICENSE) for the entire repository — specification, schemas, reference implementation, and conformance tests alike.

Why AGPL for the whole repo

AGPL-3.0 was chosen deliberately for a protocol that will often run as a network service (an MCP or HTTP SGM server):

What this means for adopters

See LICENSE for the full terms.

Reporting security issues

See SECURITY.md.