Tenant and workspace isolation
Each workspace is separated so agents only operate inside the environment they are assigned to.
Trust Layer
Duka protects organizations by giving agents access to governed knowledge objects instead of raw operational systems, inboxes, folders, social accounts, or admin tools.
Instead of connecting an agent directly to everything, Duka first processes information into controlled objects with ownership, access rules, citations, lineage, freshness, quality status, and allowed actions.
Each workspace is separated so agents only operate inside the environment they are assigned to.
Users receive answers based on permissions, workspace role, and allowed knowledge objects.
Answers can point back to files, records, conversations, or source summaries used as evidence.
Agents can surface when knowledge is current, stale, incomplete, or not strong enough to answer safely.
Skills constrain what an agent is approved to retrieve, draft, route, or execute.
Sensitive retrieval and task execution can retain traceability across users, sources, and workflows.
Duka can be delivered as managed SaaS for speed, or as a dedicated instance when policy requires stronger isolation, customer-specific deployment boundaries, or private integration controls.
If a user is not allowed to access a source, the agent should not use it. If evidence is missing or stale, the agent can fall back safely instead of inventing an answer.
Duka Agents can retrieve, explain, summarize, draft, and route tasks only through approved knowledge objects and controlled workflows.