Skip to main content

Overview

SYMI is a multi-user platform, so its security model is built around one core guarantee: your work is yours. No other user’s session can see your files, your memory, or your workspace, and you can’t see theirs — regardless of what any single request asks for. This isolation isn’t a single check performed once at login. It’s enforced at several independent layers, so that no one mistake in any one layer breaks the overall guarantee.

How isolation works, at a high level

  • Identity comes first. Before any work begins, SYMI confirms who you are from your authenticated session — not from anything supplied in the request itself. A request can’t claim to belong to a different user or a different workspace than the one it actually authenticated as.
  • Each session runs in its own isolated environment. Your conversation and any code or file operations it triggers happen inside a contained environment set up specifically for your session, with visibility limited to your own files.
  • Access is explicit, not assumed. What a given session can see or do is determined by the platform’s own configuration for that session — not by anything written in a prompt, a file, or a conversation. A file in your workspace can guide how SYMI approaches a task, but it can’t grant itself new permissions or access to someone else’s data.
  • The same boundary applies everywhere. Whether you’re chatting with SYMI, using Workspace Mirror to sync files to your own computer, or running a longer task, the same per-user ownership boundary applies. Connecting a device or starting a long-running task doesn’t create an exception to it.
These are architectural guarantees, not settings you need to configure yourself. There’s nothing for you to turn on — isolation applies to every session by default.

What this means in practice

A few concrete implications worth knowing:
  • A file you upload or a project you create is visible only to you. It doesn’t become part of any shared or global knowledge base.
  • Enrolling a computer with Workspace Mirror doesn’t widen access. A device you connect can only ever sync the workspace roots that belong to your account — see Workspace Mirror for how enrollment works.
  • Instructions inside a file or a piece of retrieved content aren’t automatically trusted the same way a direct request from you is. SYMI is designed to treat content it reads — including things recalled from memory or fetched from elsewhere — as information to consider, not as commands with the same authority as your own instructions.

Next steps

Persistent Workspace

See what’s stored in your workspace and for how long.

Workspace Mirror

Learn how device enrollment respects this same isolation boundary.