Identity and scope
Understand installation, actor, conversation, and thread identity before storing memory or authorizing effects.
Every inbound event carries a ChannelLocation. Noir does not reduce identity to a username or a channel name.
type ChannelLocation = {
channel: string
installationId: string
conversationId: string
threadId?: string
}Messages add an actor with a provider-stable ID. Together these fields form the minimum authority context for a turn.
Identity layers
channeldistinguishes adapters such as Slack and Telegram.installationIddistinguishes workspaces, bots, tenants, or provider accounts.conversationIdidentifies the direct message, channel, room, or email thread.threadIdnarrows a provider conversation when threads are supported.actor.ididentifies the sender within the installation.
Never authorize by display name. Display names can change and may collide.
Conversation serialization
Noir derives a stable conversation key from the channel location. Work sharing that key runs in order, preventing two turns from racing conversation state. Different conversations can proceed concurrently.
This key is a processing boundary, not an authorization grant. A person being able to message the agent does not imply access to every repository, billing account, or shared sandbox.
Resource scope
Memory and sandbox adapters accept explicit scopes. Common choices are actor, conversation, or installation. Use the narrowest scope that matches the product:
| Resource | Typical scope | Consequence |
|---|---|---|
| personal preferences | actor | follows one person across conversations |
| project discussion memory | conversation | shared only inside one room/thread |
| workspace glossary | installation | visible across one installed workspace |
| scratch files | actor or conversation | prevents cross-user leakage |
Authorization in code
For a repository write, verify the installation, actor, repository, operation, and target branch. For billing, use restricted provider keys and requester approval. For shared channels, consider group membership and line ownership rather than assuming the latest speaker owns previous context.
Prompts can explain desired behavior, but they cannot establish authority. Connector callbacks, policy rules, and resource adapters are the enforcement points.