SGM defines the boundaries an implementation must enforce, while leaving the mechanism implementation-specific. This document covers sensitivity metadata, authorization boundaries, and licensing.
A record MAY carry a sensitivity object declaring how it should be handled:
"sensitivity": {
"level": "confidential",
"contains_secrets": false,
"pii": true
}
| Field | Type | Meaning |
|---|---|---|
level |
enum | public | internal | confidential | restricted |
contains_secrets |
boolean | Whether the content includes credentials/keys |
pii |
boolean | Whether the content includes personal data |
An implementation SHOULD surface sensitivity to consumers and MUST round-trip
it losslessly. An implementation that detects contains_secrets: true SHOULD
warn on export but MUST NOT silently drop the field.
The protocol requires that a boundary exists and is enforced around every operation, even though the auth mechanism is implementation-specific:
scope_denied, never a
silent empty result.SGM does not mandate OAuth, API keys, mTLS, or any specific scheme. It mandates that some boundary is enforced.
contains_secrets
exists so consumers can flag and exclude them.Provenance (see provenance.md) is a security feature: because every record identifies its creator, session, and origin, a consumer can judge trustworthiness and detect records from unexpected agents. An implementation MUST preserve provenance unmodified — tampering with it would defeat this.
SGM is released under the GNU Affero General Public License v3.0 (LICENSE) for the entire repository — specification, schemas, reference implementation, and conformance tests alike.
AGPL-3.0 was chosen deliberately for a protocol that will often run as a network service (an MCP or HTTP SGM server):
See LICENSE for the full terms.
See SECURITY.md.