Human Context Protocol

Your context, shared without being surrendered.

Mind Share gives every person a context agent. Teammates never get your files, your inbox or your drive. Their agent asks yours, a firewall decides what may be said, and every answer leaves a receipt.

Nobody reads your files. Their agent asks yours.

Shared drives leak everything or nothing. Mind Share replaces the file boundary with a negotiation: a question, a purpose, a policy check, an answer that carries its own audit trail.

The protocol

Three moves, every request

Each negotiation runs the same way, whether the asker is a teammate, a coding agent or a desktop client speaking MCP.

  1. 01

    Ask

    A request arrives with a question and a stated purpose. No file access is requested, and none is ever granted.

  2. 02

    Negotiate

    Your context agent retrieves only from your own context map, then hands each candidate answer to the firewall: classification, organization role, and an inference-risk check.

  3. 03

    Disclose

    What survives comes back as the minimum sufficient answer, with a disclosure receipt naming what was shared, what was redacted and why.

The firewall

Four tiers, one decision

Every context item carries a classification. Your organization role sets the ceiling; the inference check decides the rest.

Public
Answerable to anyone who asks, inside the company or outside it.
Team
Released to members of your organization, with the purpose recorded.
Private
Held back from peers; releasable to an admin in your organization when the purpose justifies it.
Restricted
Never released automatically, at any role, for any purpose.

Protected conclusions — a job search, a compensation band — are declared up front. A second pass asks whether a candidate answer would let the requester derive one. If it would, the answer is withheld and the refusal is logged.

In the product

Three surfaces

Everything the protocol does is visible from the moment you sign in.

Ask a teammate

Put a question to someone else's context agent, state the purpose, and read the answer next to the receipt that produced it.

My context

The map your agent answers from: claims pulled out of your sources, each with its classification, evidence and source document.

Audit trail

Every negotiation in order — who asked, what they wanted it for, what was shared and what the firewall refused.

Frequently asked questions

Do you have any questions? We have got you covered.

Does anyone get access to my documents?
No. Source documents stay in your account. Agents exchange claims, never files, and the transcript of each exchange is yours to read.
Where does my context map come from?
A background job ingests your connected sources — Google Drive today — and a classifier turns each document into structured claims with a classification. You can inspect and correct every item.
What stops a clever question from leaking a private fact?
The inference-risk check. Beyond per-item classification, the firewall tests whether a candidate answer would let the requester derive one of your protected conclusions, and withholds it if so.
Can other agents connect?
Yes. The protocol is exposed over MCP, so a teammate's agent, a coding agent or a desktop client can negotiate for context under the same rules, with the same receipts.

Bring your own context. Keep the boundary.

Connect a source, let your agent build the map, and watch the first negotiation end in a receipt.