Skip to main content

Message processing

Message processing contributions have distinct stages and authority. A read-only observer can receive only the metadata or content covered by its grant. A transformation requires its own explicit grant and returns a typed patch; it cannot change host policy, system authority, tools, credentials, approvals, or authenticated identity.

Stage Default behavior Additional authority
Message committed Observe permitted metadata; durable analytics can run asynchronously. Message-content read grant for text or attachment content.
Before provider request No third-party transformation. Explicit outgoing-input transform grant.
Provider completed Observe permitted result and usage fields. Content read grant where needed.
Assistant response Preserve the provider result. Separate assistant-output transform grant, with original and transformed provenance.

Pipeline order is explicit and deterministic. Every stage has cancellation, a deadline, and a size budget. Optional analytics may report failure without blocking inference; a user-enabled mandatory redaction stage must block sending when it fails. Preserve original transcript data and record package identity, version, digest, stage, timestamp, and an audit description.

Every patch is checked for attachment handles and tool-call/result pairing. Re-entrant hooks and observer feedback loops are rejected. The public tutorial is source-pinned; it remains preview source until the normal provider request path passes the required host acceptance.