hachiflow.com
アイデンティティ

あなたのアイデンティティはであり、次のワークスペースでもすでに使える

Buzz のアイデンティティは、当社のデータベースのアカウントではなく、お客様の端末で生成される鍵ペアです。二つ目のワークスペースに参加した瞬間から、あなたはすでにあなたです。当社がワークスペースのために発行する鍵と、お客様だけのものであり続ける鍵は、意図して別物です。

Not a row in our database

Sign in to most chat products and you are a row in the vendor's user table: an email, a password hash, an id they issued. A Buzz identity is none of that. It is a keypair, generated on your own machine the first time the app runs. The public half is your ID, safe to share anywhere. The private half signs every message and action you take, and it stays in your keychain.

We never see the private half. There is no password to reset because there is no password, and no account for us to suspend because there is no account. There is a key, and it proves, mathematically, that a message came from you.

The second workspace already knows you

Here is where it stops being abstract. Join a second workspace, a client's hive, a community, a side project, and you do not create anything. You show up with the same key, an admin enrols your public ID, and you exist there. One identity, every workspace you will ever join: same name, same ID, same signature in all of them. (Buzz speaks Nostr, an open protocol, which is why the key format is standard rather than ours.)

One honest boundary: your identity travels, your messages do not. A message lives on the relay where you sent it. Getting your history out of a workspace is an export, a different mechanism with different guarantees, and joining a new workspace starts its conversation fresh.

あなたの鍵 端末で生成、当社は持ちません ワークスペース A あなた自身の鍵で参加 ルート鍵 · 当社発行、エスクロー保管 ワークスペース B あなた自身の鍵で参加 ルート鍵 · 当社発行、エスクロー保管
同じ個人鍵が、参加するすべてのワークスペースであなたです。各ワークスペースには当社が発行しエスクローで保管する専用のルート鍵があり、紛失しても取り戻せます。二つが同じ鍵になることはありません。

What we mint, and what is yours

Every workspace also has a root key: the owner key, the one that controls the workspace itself. That key we mint when the workspace is provisioned, and we place a copy in escrow. If the owner loses it, we hand it back, verified and audited. Recoverability is the point: a business should not lose its workspace because one laptop died.

Nobody works signed in as the root. Day to day, everyone in the workspace, including the person who pays for it, participates as an admin or a member with their own personal key: the one made on their device, the one we never see.

The custody line

The two keys draw one clean line. A key we hold in escrow is a key we can hand back, and that is exactly why it must never be your personal identity. Your personal key is yours alone, and that is exactly why we cannot recover it. Every recovery promise is a custody fact, in both directions.

This is also why we say plainly that we can read our escrow copy, rather than dressing it up: handing back a lost owner key is only possible while a copy we can read exists. The full detail, including how to make us delete our copy and what that costs you, is on the keys page.

Roles, in plain words

Admins run the workspace day to day: they send invites, add and remove members, and moderate. Members talk, share, and build. Both do it with their own keys.

Only the owner changes roles. That is the power the root key keeps, and it is why the recoverable key in escrow is the owner key and not anything a person carries around daily. Lose an admin's laptop and the admin re-enrols with a new key. Lose the owner key and we recover it. Nothing in that sentence requires us to hold anything that is yours.

← フィールドノート一覧