Gubbins docs Open Gubbins
The rooms

Access

Who may touch what: the people in your space, the keys your AIs hold, the providers you have shut out, and every receipt in one place.

What Gubbins promises here

Apart from whoever runs the space, nobody reaches anything here until somebody writes a line saying so. Every line, and every change to one, is on the record.

Keys

A key is how one assistant reaches your bank. You make one per assistant, so that revoking one never disturbs the others, and so the ledger can say which assistant did what.

When you make a key you narrow it: which areas it may read, and whether it may see amber memories as well as green. A key reads what it was granted and nothing else.

The token itself is shown once, at the moment it is made, and never again. Gubbins keeps only a hash of it, so a key that is lost is replaced rather than recovered. Revoking a key takes effect immediately.

The first package a new key would be given waits for your approval in Review before anything leaves.

A key's drawer lists the attached tools it could call, each with a tick. A tool that changes things at the other end is allowed for one key at a time here, never by the fact that the key runs under you, and the row says what the server claims it changes. Each key's first call to each tool is held for your look in Review.

Connecting by sign in

An AI app can also reach your Memory without a key being pasted anywhere. It asks to connect, your browser is sent to a page in Gubbins that names the app and says where you will be sent back to, and you make the same choices you make for a key: the whole Memory or scopes you pick, amber or not, and when it ends. Say yes and the app is connected; say no and it is turned away. Either way the ledger has a line for it.

A connection is listed under Keys like any key, marked connected by sign in, and everything true of a key is true of it: the first package is held for your look, every read is receipted, and a provider ban that names its label stops it. Disconnecting it is the same button as revoking a key, and it does one thing more: the app's sign in is cancelled at the door, so it cannot quietly renew. It can ask to connect again later, and that is a new decision.

An app that asks again while it is already connected is sent straight back without a page, because there is nothing new to decide. To end it, disconnect it here.

People

A space can have more than one person in it. Nothing is shared by default: with no lines written, the only person who reaches anything is whoever runs the space.

A line says that a named person may do a named thing with a named part of your Memory. Lines are written and taken back one at a time, and every one of them, along with every change to it, lands in the ledger.

Most spaces have exactly one person in them today, which is why the People view usually says nobody has written a line yet. That is the safe state rather than a gap.

Shut out

A refusal is stronger than the absence of a permission. Shutting out a provider says that no key belonging to them may read a given part of your Memory, whatever else is granted, and it holds even if somebody later writes a line that would have allowed it.

It is the control to reach for when the answer is not "not yet" but "not them".

The one ledger

Everything that happened is in one list, newest first: what your AIs did, changes you made in the Vault, keys made and revoked, and every change to who may reach what.

There is one ledger in Gubbins and this is it. A record that lives in two places is a record that disagrees with itself.

What a receipt says

A receipt names who acted, what they did, when, and enough about it to be meaningful: which assistant read your Memory, how many memories it was given, what it asked about, and how many were held back or masked on the way out.

A receipt never carries a credential, any part of one, or anything that could be turned back into one.

What you can see

The ledger can be filtered to your AIs, to Vault changes, to keys, or to permissions. What each person may read of it follows the same rules as everything else: you can always read your own acts, and a receipt about a secret is visible only to somebody entitled to know that secret exists.

Finding something

Each of the four lists has a search box, and it narrows what is already in front of you. It can only hide a row, never surface one: what you may see is decided before the search runs, so searching cannot be a way of finding out that something exists.

Leaving

Everything in your bank can be exported as one file, and closing your account removes it. Neither is buried: the point of a bank you own is that you can walk out of it with everything in it.

Where it is

Access is the fifth room in the app. Open Gubbins.