Your app keeps control
Pult never connects to your database or your infrastructure. Everything it knows about your records comes from functions in your app, and everything it does to them is an action your app runs and can refuse. If you remove an action from your code, nobody can run it, whatever their role.Signed both ways
Every request between your app and Pult is signed with your environment’s key, using HMAC-SHA256 over the method and path, a timestamp, a one-time nonce and the body. Pult refuses requests that are unsigned, altered, more than five minutes old or seen before, and the SDK applies the same checks to requests from Pult. Keys are stored encrypted, can be rotated at any time, and each environment has its own.Permissions live in code
Roles, and which inboxes, resources, actions, pages and flags they grant, are defined in your repository and reviewed like any other change.pult diff shows who gains or loses which permission before you deploy. People are assigned roles in the console; agents get exactly one role each.