Security · Privacy · Governance

Built to be trusted by default.

Ashcroft treats automation as a privilege, not a default. The platform is built to read before it writes, to fail closed, and to leave durable records of governed activity.

The commitments

How control actually works.

Governed actions are permissioned.

Connected capabilities operate within the permissions you grant, and higher-consequence actions can require approval before they run.

Actions leave a trail.

Governed execution creates durable records so you can inspect what was authorized, what ran, and what happened.

Connections are controllable.

Permissions and connected accounts can be reviewed and revoked as your needs change.

Connection ownership

Four kinds of connections, four separate owners.

It is always clear what a credential does, and adding one kind of connection does not quietly enable another.

Your identity

How you sign in. It proves who you are, nothing more.

Your data

Your mailbox and calendar, a separate step with its own consent. Signing in never reads your mail.

AI providers

Separate from your login: Ashcroft-managed infrastructure, approved local models, or a provider your organization connects, protected server-side.

Agent permissions

Which capability each agent may use. Connecting a provider does not automatically grant it to anything.

Whose world is it?

Ownership is always clear.

Your Everyday account belongs to you.

Your personal memory and information remain part of your personal environment.

A Work environment belongs to the professional or organization.

Membership, permissions, and shared knowledge are governed inside that environment.

The two do not become one database of your life.

Using Ash in both places does not automatically make personal information available to an employer, or organizational information available to your personal Ash.

Client contexts are separated the same way: organization isolation keeps each client's environment its own, and information crosses a boundary only when authorized, visibly and revocably. For readers who want the mechanism: state changes in the governed pipeline are policy-checked and recorded, work is routed by rule, and governed actions execute behind approval gates.