NOIR
Core concepts

Identity and scope

Understand installation, actor, conversation, and thread identity before storing memory or authorizing effects.

Every inbound event carries a ChannelLocation. Noir does not reduce identity to a username or a channel name.

type ChannelLocation = {
  channel: string
  installationId: string
  conversationId: string
  threadId?: string
}

Messages add an actor with a provider-stable ID. Together these fields form the minimum authority context for a turn.

Identity layers

  • channel distinguishes adapters such as Slack and Telegram.
  • installationId distinguishes workspaces, bots, tenants, or provider accounts.
  • conversationId identifies the direct message, channel, room, or email thread.
  • threadId narrows a provider conversation when threads are supported.
  • actor.id identifies the sender within the installation.

Never authorize by display name. Display names can change and may collide.

Conversation serialization

Noir derives a stable conversation key from the channel location. Work sharing that key runs in order, preventing two turns from racing conversation state. Different conversations can proceed concurrently.

This key is a processing boundary, not an authorization grant. A person being able to message the agent does not imply access to every repository, billing account, or shared sandbox.

Resource scope

Memory and sandbox adapters accept explicit scopes. Common choices are actor, conversation, or installation. Use the narrowest scope that matches the product:

ResourceTypical scopeConsequence
personal preferencesactorfollows one person across conversations
project discussion memoryconversationshared only inside one room/thread
workspace glossaryinstallationvisible across one installed workspace
scratch filesactor or conversationprevents cross-user leakage

Authorization in code

For a repository write, verify the installation, actor, repository, operation, and target branch. For billing, use restricted provider keys and requester approval. For shared channels, consider group membership and line ownership rather than assuming the latest speaker owns previous context.

Prompts can explain desired behavior, but they cannot establish authority. Connector callbacks, policy rules, and resource adapters are the enforcement points.

On this page