Access and policy decisions are separate

Signing in, reading a record and an adapter decision are three separate checks.

Sign in with Google or an email code

Signing in opens your account. It installs nothing in an agent client; the adapter is a separate install.

Reading a record is checked on the server

Every read of a product record is checked against your account and its permissions on the server, whatever the page shows.

An adapter decision happens on the machine

The adapter decides each command from your org’s signed policy, on the person’s machine, before it runs.

A decision is not completion

An allow or exception decision authorizes a defined action. It does not prove that the action ran or succeeded. Execution needs its own result record.