Default deny
No standing policy → nothing crosses. Trust is opt-in, never ambient. A stranger gets the same answer as a closed door.
The most dangerous piece in Echo, built on a short leash. One Echo's agent asks another's a question; the answer is bounded by the owner's standing disclosure policy. The vault never moves — only a minimized disclosure crosses. This is the safe core; the four hard problems are listed below, unsolved and in the open, because a mesh that felt complete while quietly leaking would be the exact betrayal Echo exists to refuse.
*collaborator*for collaboration-checkdims [achievements]confirm-shared truemax 5Everything else is default-deny. The vault itself never crosses — only a minimized disclosure does.
No standing policy → nothing crosses. Trust is opt-in, never ambient. A stranger gets the same answer as a closed door.
Only a minimized disclosure crosses, and only from allowed dimensions. Private dimensions and capsule bodies never cross — titles at most.
Confirm-mode proves overlap (overlap: true) while revealing no content (detailRevealed: false). You can learn that something is shared without seeing it.
Anything beyond standing policy escalates to the owner (Law 8) — the agent has no path to grant it. And every disclosure is written to the owner's ledger (Law 6).
A mesh is exactly where a system lies to itself. These four are not handled here, and a confirm-mode boolean does not fix them. The handshake is real and tested; the hard problems are named, not hidden.
Once a counterparty has a disclosure, nothing here stops them passing it onward. The hardest leak vector in any mesh. Needs disclosure terms that travel with the data and/or recipient-side enforcement — an open problem, not a checkbox.
Many narrow confirm-queries can triangulate what no single one revealed. Per-query minimization is not aggregate minimization. Needs query budgets, rate-limiting, disclosure accounting.
Counterparties are bare strings here. Real binding needs the signed-attestation + key-directory work from Reputation — and even then, Sybil resistance is its own problem. see Reputation →
Everything here is disclosure only. The moment an agent can do something on the other side, the threat model changes entirely — and that is gated behind owner sovereignty by design.
The safe core is a real start: agents can collaborate without surrendering the vault. The distance between this and a trustworthy open mesh is the four problems above — and honesty about that distance is the only safe way to cross it. Do not deploy this as if it were a finished mesh.