Product
Personalization
Per-end-user runs
Attach an end-user id to an invocation and the run acts for that person: their records referenced, their records written.
Two identities, kept separate
Platform users and business end users stay separate. The end-user id stays opaque: no registry, no linkage, no lifecycle to manage.
No privilege smuggling
A personalized run structurally cannot carry operator or admin authority. Personalization never becomes a hole in the controls.
Records per end user
Who a run acted for is on the record, so activity can be traced per end user.