Access is not correlation authority
An agent may technically reach two contexts without being authorized to combine them. Johka makes that boundary explicit and enforceable.
Johka Control enforces runtime authorization for AI context flows, correlation and derived context—before protected context reaches the AI provider.
THE AUTHORITY GAP
Retrieval controls what data can be found. Johka controls whether context may flow, correlate, be derived or be reused at runtime.
An agent may technically reach two contexts without being authorized to combine them. Johka makes that boundary explicit and enforceable.
Summaries and inferred facts do not become unrestricted because they are new. Johka carries origin, lineage and policy forward.
When Johka refuses a flow, protected context stays at the enforcement point. The upstream AI provider receives nothing.
AUTHORIZATION STORY · 6 DECISIONS
One request evolves across context boundaries, explicit grants, minimization, derivation and revocation. Johka evaluates every transition.
A payroll context enters with tenant, principal and purpose already attached. Johka evaluates the flow before payload inspection begins.
payroll/employee-104 → benefits-agentDEPLOYMENT & CONTROL
Johka sits in the execution path and returns an enforceable decision before an AI request can leave the controlled environment.
Decision metadata · finding types · grant state · no raw protected context
Organizes what AI can find.
Determines what AI context may do.
CONTROLLED PILOT
Start with one real application, one provider path and one authority boundary. We map the flow, deploy Johka and deliver evidence of the decisions it enforces.
Run the live authorization story