MENSARA.AI · A GOVERNED MIND, IN YOUR ACCOUNT

The bargain · Held at the gate

What it will not do.

Two questions come up before any other: where did the Mind get that answer, and who else can reach it. The first has its own page. This one is the second question, put in plain language rather than left to a footnote: what your Mind refuses, and what we ourselves cannot do.

01

The door doesn't open by accident

Every request to your Mind starts from zero. Nobody gets in because a zone was left open by mistake, and no agent inherits access it was never given. A person or a process has to be granted a specific zone, by name, before a question can be answered from it.

Say a contractor joins your Mind with access to the client-facing zones and nothing else. They ask a question that would need the pricing model, kept in a zone they were never granted. The gate does not weigh how reasonable the request sounds. It refuses, the same way it would refuse a stranger who wandered in off the street. There is no ambiguous middle case where it guesses in your favor.

02

New capability starts on probation

Nothing gets to act inside your Mind at full trust on its first day. New code, a new automated behaviour, a new integration all arrive through what we call the airlock. Each is reviewed before it runs and starts at the least trust that lets it do anything useful at all.

Trust after that is earned on a track record, not granted at install and left alone. Update something that already earned trust and the update goes back through the same door: being established once does not exempt anything from being checked the next time it changes. Nothing is grandfathered in quietly.

03

What we can see, and what we structurally cannot

Once your Mind is set up, Mensara's own infrastructure holds no standing credential that could open it. The boxes running your Mind reach out to us, using tokens that expire quickly and are replaced. We do not reach in.

That is not a setting we could change on a bad day, and not a rule a new hire could quietly override. It is the direction the connection runs. Our central infrastructure has no standing way to read into your Mind, because the architecture never gave it one to begin with. You are not trusting a policy here. You are trusting a shape.

Certain rules about how your Mind is allowed to behave sit above even that. Changes to them go to a human for review every time, with no fast path, regardless of how much trust anything else in the system has earned elsewhere.

04

Refusals are not silent

When something is denied, held at the gate, or simply goes wrong, that event gets a receipt of its own. It is not swept aside just because the action never went through. You can find it later, see exactly what was asked, and see exactly why it did not go through.

You have already seen one of these, on the Receipts page: a real denied read against a zone marked secrets, chained directly to the allowed request that came before it. This page will not repeat that artefact. The mechanism behind it is the one this page has just described, and the refusal it shows is the same kind.

I decided early that Mensara should not be able to open your Mind. Promising not to is not the same thing: a promise depends on who is keeping it, and that is not something I was willing to ask you to take on faith.

ANTONY · FOUNDER

FILED

running since 2026-05 · deny-by-default and the airlock are live · the boxes-dial-out boundary is architectural, not a policy that could change

NEXT Questions The questions people ask before they say yes →

The founding cohort is small on purpose. Each Mind is brought up personally.

MENSARA.AI · HELD AT THE GATE · MACHINE SURFACE · TEXT/MARKDOWN

# Held at the gate

> Mensara's Mind denies access by default. New capability enters through a reviewed airlock that starts at minimal trust and earns more on a track record. The boxes running a Mind dial out to Mensara on short-lived tokens; Mensara holds no standing access in. Refusals and failures are receipted like any other event.

Canonical: https://mensara.ai/how-it-works/governance

## The door doesn't open by accident

Every request to your Mind starts from zero. Nobody gets in because a zone was left open by mistake, and no agent inherits access it was never given. A person or a process has to be granted a specific zone, by name, before a question can be answered from it.

Say a contractor joins your Mind with access to the client-facing zones and nothing else. They ask a question that would need the pricing model, kept in a zone they were never granted. The gate does not weigh how reasonable the request sounds. It refuses, the same way it would refuse a stranger who wandered in off the street. There is no ambiguous middle case where it guesses in your favor.

## New capability starts on probation

Nothing gets to act inside your Mind at full trust on its first day. New code, a new automated behaviour, a new integration all arrive through what we call the airlock. Each is reviewed before it runs and starts at the least trust that lets it do anything useful at all.

Trust after that is earned on a track record, not granted at install and left alone. Update something that already earned trust and the update goes back through the same door: being established once does not exempt anything from being checked the next time it changes. Nothing is grandfathered in quietly.

## What we can see, and what we structurally cannot

Once your Mind is set up, Mensara's own infrastructure holds no standing credential that could open it. The boxes running your Mind reach out to us, using tokens that expire quickly and are replaced. We do not reach in.

That is not a setting we could change on a bad day, and not a rule a new hire could quietly override. It is the direction the connection runs. Our central infrastructure has no standing way to read into your Mind, because the architecture never gave it one to begin with. You are not trusting a policy here. You are trusting a shape.

Certain rules about how your Mind is allowed to behave sit above even that. Changes to them go to a human for review every time, with no fast path, regardless of how much trust anything else in the system has earned elsewhere.

## Refusals are not silent

When something is denied, held at the gate, or simply goes wrong, that event gets a receipt of its own. It is not swept aside just because the action never went through. You can find it later, see exactly what was asked, and see exactly why it did not go through.

You have already seen one of these, on the Receipts page: a real denied read against a zone marked secrets, chained directly to the allowed request that came before it. This page will not repeat that artefact. The mechanism behind it is the one this page has just described, and the refusal it shows is the same kind.

**Status:** running since 2026-05 · deny-by-default and the airlock are live · the boxes-dial-out boundary is architectural, not a policy that could change

## Prompt

```prompt
Ask your Mind to list which capabilities are currently trusted, and how much trust each one has earned so far. Then ask it to show you the most recent request it refused, and why.
```

## Related

- [Receipts](https://mensara.ai/how-it-works/receipts)
- [Yours, provably](https://mensara.ai/how-it-works/ownership)
- [Questions](https://mensara.ai/how-it-works/questions)