Skip to content
One stable identity Human-authored by default Portable by design
Topoloom by Relia1

Trust by design

Trust begins with a visible boundary.

Topoloom keeps human declarations, machine suggestions, bindings, and externally verified context distinct—across authoring, review, publication, and export.

Human-authored
Declared ServicePayment Service

Owner · Payments Team

Published v8 · Maya Chen
External context
Observed differenceRuntime owner differs

Suggested — not declared

Provider assertion · 2 min ago
Authored stateAttributed context

Knowledge-state legend

Trust has more than one axis.

Authorship, version lifecycle, and external context answer different questions. Each state uses words, a mark, and a pattern—not color alone.

01

Authorship

What has a person actually confirmed?

01

Free-form

Readable working content before formalization.

02

Suggested — not declared

A visible proposal awaiting authorized action.

03

Declared

Confirmed by an authorized person.

02

Version lifecycle

Which intentional version is current?

04

Published

An immutable, intentional version.

05

Superseded

Preserved history that is no longer current.

03

External context

What comes from a named provider?

06

Bound

Mapped to attributed external context.

07

Verified by provider

Asserted by a named provider at a stated time.

Mechanisms, not adjectives

Trust is visible in how the system behaves.

01

Human control

No silent mutation.

AI and connected systems can assist or suggest. They cannot decide permissions, approval, publication, or verified status.

02

Permissions

Access follows the knowledge.

Reads, search, references, reviews, exports, events, and external-context actions remain permission-aware.

03

Stable identity

Identity survives change.

Artifacts, content nodes, objects, relations, and versions remain distinguishable through their lifecycle.

04

Immutable versions

Publication is an explicit boundary.

Provenance, review, and audit history stay attached to the version they describe.

05

External context

Bindings do not prove truth.

Provider projections, evidence, and credentials remain outside authored document state.

06

Provider independence

Local work keeps working.

Writing, collaboration, review, history, publication, and portable export do not depend on a context provider.

Enterprise controls you can inspect

Governance is a behavior, not a badge.

The same authority boundary follows knowledge through writing, search, review, publication, integration, and movement between systems.

01

Tenant isolation

Workspace scope is enforced before retrieval, projection, export, event delivery, or provider access.

02

Permission-aware surfaces

Search results, references, graph navigation, reviews, and generated views reveal only currently authorized detail.

03

Immutable versions

Published versions remain addressable with provenance, review, audit, and contract context attached.

04

Retention and lifecycle

Archive, restore, supersession, tombstone, retention, and deletion remain explicit and auditable.

05

Public integration contracts

First-party and third-party consumers use the same versioned APIs, events, and permission boundary.

06

Portable Knowledge Package

Readable content and machine records move with explicit omissions, redactions, remappings, and permission reports.

Designed to fail safely

A dependency can fail without taking authorship with it.

External systems may enrich the workflow, but they do not decide whether local work can be written, reviewed, or preserved.

ConditionWhat keeps workingWhat is suppressed or labeled
AI unavailableAuthoring, collaboration, permissions, review, publication, and exportSuggestions and generated assistance remain unavailable; no decision is fabricated
Context provider unavailableDocuments, diagrams, objects, history, semantic diff, and local exportExternal projection becomes stale or unavailable and remains outside authored state
Search or projection index unavailableAuthoritative PostgreSQL-backed work and immutable versionsDerived discovery views degrade and rebuild later; they never become a source of truth
Permission revokedAuthorized local content and non-sensitive source textCached projection and hidden target details disappear without an existence signal

Non-negotiable boundaries

What Topoloom will not do.

  1. 01

    Silently mutate authored or published knowledge through AI or an integration.

  2. 02

    Present imported, inferred, or observed information as a human-approved declaration.

  3. 03

    Bypass public contracts with privileged direct database integration.

  4. 04

    Retrieve restricted knowledge first and filter permissions afterward.

  5. 05

    Trap the customer in a rendered-only or opaque export path.

Portable knowledge

Readable by people. Inspectable by machines.

Published packages can carry readable content and versioned structure, with explicit redactions, remappings, omissions, and permission reports.

topoloom-export / v8Versioned manifest
  • content/overview.mdReadable content
  • objects/services.jsonStable IDs
  • relations/declared.jsonProvenance
  • reviews/semantic.jsonChange history
  • permissions/report.jsonExplicit mapping
5 recordsPortable package

Topoloom records declarations made by authorized people.

Connected providers can report evidence or verification.

Provider context becomes authored knowledge only when a person accepts it as a declaration.

Request a demo