Better signal
Live, structured, user-maintained context — not stale forms or siloed copies.
Autograf
For services & developers
Users hold structured, live context in Work · Personal · Services. You integrate via offers or computation contracts — query in place, return approved results, write back into Services. Compete on intelligence, not database size.
Why integrate
Offer better services with user-permissioned data — without storing the liability yourself.
Live, structured, user-maintained context — not stale forms or siloed copies.
Query in place under contract. No warehouse to breach, erase, or audit.
Integrate once via manifest. Skip duplicate collection, storage, and DPO overhead.
Purpose, space scope, permission tier, and consent ledger — user approves every relationship.
The shift
Old model
Permanent copy in your warehouse. Stale the moment it lands. Liability on you.
Autograf
User approves purpose and space. You query live at source. Return the result — optionally write insights back. Not the vault.
How it works
The user is the root database. You are a temporary processor — query live, deliver value, optionally write back.
Offer / approve
Company steward sends an offer link, or the user creates a contract — purpose, spaces, and permission tier.
Read
Partner queries scoped context live — usually Work — via manifest + query API, no warehouse copy.
Deliver
Your product returns value: recommendation, eligibility, automation.
Write back
Optional insights land in the user’s Services space under delegated write — never auto-contributed to company.
Audit
Every read and write visible in Exchanges and the consent ledger. Revoke anytime.
Users can test the loop with the built-in Autograf demo: Try the demo exchange.
Integration paths
Company stewards create /offer/offer_… links. Customers accept into Work (read) + Services (write-back). Fastest path to enable users.
Company detail → Customer edge →User creates a contract with counterparty, purpose, space, and permission tier. You receive manifest and query URLs.
Contracts in dashboard →GET /api/share/[token]?format=manifest returns capability document. POST /api/share/[token]/query runs scoped computation.
Shares in dashboard →Connect Cursor, Claude Code, or custom agents via OAuth-scoped MCP grants. Activity lands in the user's graph under contract.
MCP in dashboard →Full bidirectional loop: query scoped context, deliver value, optionally write insights back into Services. Users see both directions in Exchanges.
Exchanges in dashboard →Developer quickstart: autograf/docs/integrating-services.md in the repo · Concept: concepts/computation-contracts.md
Use cases
Read travel history and calendar under family space. Suggest options — never sell the profile.
Query financial space for a computation. Return yes/no — not full transaction history.
Read work space for project context and hours. Prepare meetings without uploading everything.
Cursor, Claude Code, and custom agents connect via scoped MCP grants.
Read dietary context for meal planning; write lab summary back into Services under delegated write.
Permission tiers
Map technical permissions to tiers your users can approve with confidence.
Local only
Data stays in the user's space. Read and query — nothing exported.
Private compute
External AI can answer questions. Raw data is not stored outside the space.
Approved export
Specific outputs can leave. Query plus controlled export.
Temporary access
Expires automatically. Good for trials and one-off checks.
Delegated write
Can write insights back into the user's graph with provenance.
Sensitive data
Health, finance, or legal spaces — extra confirmation required.
User-side first
Single-player value — private AI memory — creates the structured graph companies later query.