# Core concepts

> Understand workspaces, identities, and the boundary between memory and action.

## Your workspace

A workspace is Orbit’s ownership boundary. Every contact belongs to one workspace, and authentication determines which workspace an agent can access. Supplying another workspace ID in a tool call does not grant access.

The first installation has one workspace, provisioned through the CLI. Public signup and workspace switching are outside the current release.

## An agent is an identity

An agent identity represents an authenticated caller, not a running process or model. Two sessions can use the same identity, but separate agents should have separate tokens for attribution and revocation.

Every CRM mutation records the authenticated actor. Updates require the revision the agent last read, preventing a stale edit from silently replacing newer information. An agent cannot choose a different author by submitting a name or ID.

## Records outlive conversations

Contact identifiers are stable, opaque UUIDs. Email addresses and names help find possible matches, but neither is a primary key. A contact without an email address is valid.

The same record remains available when an agent disconnects, starts a new conversation, or switches its underlying model.

## Time and revisions

Orbit stores timestamps in UTC. The workspace timezone records the user’s intended local context and defaults to Europe/London.

Mutable records start at revision `1`. Updates and archive/restore operations require `expected_revision`; stale edits fail with `revision_conflict`. Real changes increment the revision; no-ops do not. Archived records are excluded from ordinary reads, while their history is retained. Activity bodies are append-only through MCP and corrections are new entries; exceptional administrator redaction is audited.

## Memory is not permission

Stored text is record content. It does not authorise an agent to send a message, run code, or act on another system.

Orbit does not host an LLM, execute agent workflows, send communications, or wake an agent. Hermes and other external clients supply those capabilities under their own user authorisation.

> **A deliberate boundary**
> Orbit owns records, relationships, access, and state. Your agents own reasoning and external execution. The documentation never reads your live CRM data.

## Assignment and execution ownership

Assignment records who is intended to do a task. A claim temporarily reserves execution for one authenticated agent. Claims expire without a scheduler; renewal must happen before expiry. Every new claim has its own ID and recorded attempt. Completion requires a current claim and a linked outcome entry.

A claim cannot make an external action happen exactly once. After an interruption, inspect the previous attempt and the external system before retrying. Orbit neither authorises nor performs that action. See [Tasks](/docs/tasks).
