Official OAuth only
Provider connections use approved OAuth flows and minimum required scopes. Traditional login automation is excluded.
Security boundary
Synquestra is being built as a controlled publishing system—not a browser bot, credential-sharing tool or shortcut around provider review.
Provider connections use approved OAuth flows and minimum required scopes. Traditional login automation is excluded.
Access and refresh tokens must never be placed in browser storage or exposed through frontend variables.
Synquestra uses its own database. RAQOZ, CostGrid and external workspaces do not share product databases.
Workspace and brand membership narrow what a user can connect, approve, publish or analyse.
Maker-checker can prevent authors from approving their own work. Assisted publication requires explicit confirmation.
Material permission, connection, approval and publishing events are designed to leave auditable evidence.