Build
Components run inside a Clean Room
Your component is confined to a clean-room contract: it may touch only what it declared up front, and the platform enforces that. The lightest components reach the outside solely through a single guarded channel — the broker — which lets through exactly what was declared; heavier components run in a locked, certified container holding just their declared capabilities. Either way, anything you didn’t declare is out of reach. (The fullest form — a component with literally no socket at all — is the target tier, still being built; see Zero-Trust.)
You declare five things
- Reads — which kinds of governed data you may read.
- Writes — which kinds you may write (every write is stamped as coming from your component).
- Egress — which outside websites you may call, and how often.
- Secrets — which keys you need; the platform supplies only those, from the vault, at run time — never baked into your code or image.
- Subscribes — the events your component reacts to. You name an event and a governed verb; the platform auto-wires that into a subscription at install, so your component runs whenever the event fires.
You write these in the component’s description file (see Anatomy). They become the component’s permissions — checked when it’s signed, and enforced every time it runs.
This is the core safety promise: a tenant can read your permissions before installing you, and know that is the complete list of what you can do. The Zero-Trust deep dive has the details.