> ## Documentation Index
> Fetch the complete documentation index at: https://docs.soterislabs.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Access model

> Who can reach which surface, and why access is not the same as disclosure.

Access to Soteris is tiered. Each tier reaches a different slice of an engagement. The tier describes who is reading. It does not change what a field is: sensitive material stays sensitive regardless of who is permitted to reach it.

## Tiers

| Tier             | Reader                                   | What may be visible                                                                  |
| ---------------- | ---------------------------------------- | ------------------------------------------------------------------------------------ |
| Public           | Anyone, unauthenticated                  | These docs, and public verification of a released record's metadata.                 |
| Partner          | An integrated partner system or operator | Agreed lifecycle state and record shapes for shared engagements, within the mapping. |
| Agent-readable   | An agent acting within a granted scope   | Lifecycle state, record shapes, and status. Never internal judgment logic.           |
| Soteris internal | Soteris operators and reviewers          | Full engagement context, private working state, and review authority.                |

## Access is not disclosure

A tier decides who can reach a surface. It does not decide what belongs on the surface. Soteris keeps internal methodology, review reasoning, and client data off public and agent-readable surfaces at authoring time, not behind permissions. If access control failed tomorrow, nothing on those surfaces would expose the judgment layer.

Two rules therefore apply to every surface, and both must hold:

<Info>
  1. The [Disclosure boundary](/start/disclosure-boundary) governs what may exist on a surface.
  2. This page governs who may reach it.
</Info>
