Runtime security hardening
September 2026- Governed agent identity and organization binding tightened.
- MCP API-key authorization bound to the authenticated organization and governed identity.
- Governed invocations and decisions now fail closed when required persistence or state transitions fail.
- Atomic observation completion added so runtime evidence and observation state cannot silently diverge.
- Internal SECURITY DEFINER functions were reduced, scoped, or converted to SECURITY INVOKER where appropriate.
- Public share and guest-memory RPC boundaries were tightened and audited.
- Supabase database security boundaries and RPC grants were reviewed against the production runtime.