Concepts
Account scoping
How tokens are bound to the accounts you select, and why an agent can't reach an account you didn't connect.
Every connection is bound to a specific set of accounts. When you authorize a platform, NotFair shows the full list your identity can reach and you pick the curated subset NotFair is allowed to operate on. That subset is the access boundary.
One active account per call
Tools act on one active account at a time. You can target a specific connected account per call, but an agent can never reach an account you didn’t connect — the server rejects out-of-scope requests rather than trusting the path.
Workspaces
Connections are owned by a workspace, not an individual, so a team shares one set of connected accounts and one usage pool. Tokens are bound to the workspace at authorization time; switching workspaces requires re-authorizing.