Security boundaries you can understand
OKO separates organizer access, workspace roles, viewer activity, and AI credentials so each operation can be checked against the permissions it actually needs.
Identity and access
Organizer accounts and team roles limit who can view or change each workspace and event. Server-side checks verify access for protected operations.
Data boundaries
Event settings, reports, live presence, chat, and uploaded assets are kept in separate stores with access rules suited to each data type.
MCP access
MCP keys are scoped, revocable credentials. Requests pass through the OKO platform and its authorization rules; the client does not receive direct administrative Firebase access.
Changes and recovery
High-risk authentication and permission changes are released separately, checked before promotion, and prepared with a rollback path.
Coordinated reporting
Potential vulnerabilities and suspicious account activity can be reported to security@okostream.app. Reports are reviewed through a dedicated mailbox.