Live demo · no signup

Paste one link.
Your AI knows your company.

Signpost is the memory of your company. People keep it correct. You give an assistant one link, and it reads only the notes you chose.

Demo sign-in — founder@signpost.demo · waymark · three accounts, and each account sees a different set of notes

This URL is everything the assistant needs
signpost-demo.theserverless.dev/s/sp_live_7Kd2mQwEr9TyUiOpAsDf…

One URL. It is the credential, the permission set, the route and the contract at once. Paste it into ChatGPT, Claude or a terminal agent. The assistant reads the briefing and starts work. You install nothing. Your contractor makes no account.

Test the scope yourself Ask the assistant about pay bands. It answers that the note exists, that this link cannot read it, and that Ankur Singh holds it.

Watch one link start a contractor.

Recorded against this instance, in one take. The conversation in the middle is a real one, held twice through the same link — once in a ChatGPT temporary chat and once in a fresh Claude chat. Neither was told what to say.

A permissioned memory for your company, and a protocol for any assistant.

People hold the canonical notes. You hand an assistant one scoped URL. That URL carries four things at once, so it needs no tool and no account.

A credential

The token sits in the path. The assistant sets no header and signs no body. Any client that can fetch a URL can use every verb.

A permission set

The link carries a grant, not raw access. A grant names the mode, the notes, the account and the expiry. Signpost builds the grant again on every request, so a change takes effect at once.

A route

A person writes the reading order. The briefing sends the assistant to the map of the wiki first, and to search last. The build fails when a route names a note that does not exist.

A contract

The same briefing lists the verbs and what each one will do to each note. tools.json carries the same verbs as schemas, for a model that prefers a schema.

Three steps. In the third step the assistant writes back.

Most tools stop at read access. The value arrives when the assistant writes back, and the note decides what happens to that change.

01

Mint a scoped link

Open a note and press Share. The link carries that note and the pages inside it. Choose read-only or contributor, and choose an expiry. A sealed note never enters a link, even when you can read it yourself.

02

Paste it into any chat

The assistant fetches the briefing, learns the verbs, and answers from your notes. It cites a note id for every claim.

03

One call writes back

The assistant calls write once. It never chooses between an edit and a proposal. The note's policy decides, and the answer says whether Signpost saved the change or queued it.

Three questions, asked separately, for every note.

Most tools ask one question and call it access. Signpost asks three: who reads it, whether an assistant may read it, and what Signpost does with a change. They are different questions, so they get different answers.

Audience

company · invited

Every person with an account can read a company note. Signpost never shows it to the public internet. Only the owners of an invited note, and the people they invite, can read it.

AI

open · escorted · sealed

This setting never limits a person. A sealed note enters no link, ever. An owner can create an escort link, and that link carries an escorted note for 60 minutes.

Change

direct · reviewed · locked

direct saves at once. reviewed sends the change to the queue. locked refuses every writer except an owner.

The review limit

An agent never applies a change to a reviewed or locked note, whatever role its link carries. The change goes to the review queue. No text that an agent wrote becomes the live version until a named person accepts it.

A link can narrow access, never widen it

A link acts as the account that minted it and inherits that account's roles. You can narrow a link. You can never widen one. Deactivate an account, and every link that account minted stops on the next request.

Check it: press Share on a sealed note. The modal explains that no link can carry it, and offers nothing. The briefing prints the grant that Signpost built for the link.

A secret project, and an assistant that will not guess.

This wiki holds a real unreleased project. Its evaluation note is escorted, so no standing link carries it. Watch what an assistant does when it meets that note.

What ChatGPT said, unprompted

“There is a third failing beta gate, but this link does not let me identify it reliably. The actual gate table is in labs/atlas/evaluation, which this share link marks closed to AI; it says Ankur Singh can provide a 60-minute escort link. So I wouldn't invent the third failure.”

Why that answer matters

The assistant found a gap in the numbers. It located the note that would close the gap. It knew that the link cannot carry that note. It named the owner and the remedy. Then it refused to fill the gap.

An assistant that says “the wiki does not say” about a note you can open in the next tab gives you a false answer. Signpost tells the assistant the note exists and is closed, so the answer is useful instead of misleading.

The wiki states what it does not know.

An assistant invents an answer when it finds nothing. Signpost gives it something better to say, and a route to the right note.

Gaps rank beside claims

The recall verb returns ranked passages and a list of gaps. A gap is a term in the question that no readable note holds. The assistant reports it. It does not fill it.

A route beats a search

Every note ends with a Read next list that a person wrote. The briefing sends the assistant along the route first. The build fails when a route names a note that does not exist.

A citation for every claim

Each answer names a note id, such as brand/identity. You check the source in one click. The meter shows how many tokens of note text the answer used.

Every version names the person and the session.

Other tools record who changed a note. Signpost records who changed it and which assistant session made the change. Both names stay with the version.

Two names, never null

A version holds the account, the assistant, the session and the time. Signpost mints the session id, so no client can fake it. The assistant supplies its own name, and a client can fake that name. Signpost shows the session id first, and the name second.

One table, three jobs

History, the review queue and attribution are one table. A proposal is a version that waits for a decision. The proposal already holds the full new body, so Signpost makes one update. There is no patch to re-apply.

A ledger you can check

Signpost hashes every new link, every revocation, every write and every decision to the entry before it. The Activity screen recomputes the chain and names the first entry that does not match.

Six waymarks. Each one says where a claim came from.

A waymark is the small mark that Signpost draws beside a claim. Two parts carry meaning, and they are independent. The post colour says who wrote the claim. The chevron says whether a person verified it.

A person wrote it, and a person verified it
A person wrote it, and a person verified itPost trail green · chevron filled
A person wrote it. Nobody verified it
A person wrote it. Nobody verified itPost trail green · chevron hollow
An agent wrote it, and a person verified it
An agent wrote it, and a person verified itPost slate grey · chevron filled
An agent wrote it. Nobody verified it
An agent wrote it. Nobody verified itPost slate grey · chevron hollow
It is stale. Nobody has checked it recently
It is stale. Nobody has checked it recentlyPost amber · chevron hollow
It conflicts with another claim
It conflicts with another claimPost red · chevron a cross

Rows one and three share a filled chevron and differ only in the post. A person verified both claims. A person wrote the first claim, and an agent wrote the third. Colour is never the only signal: every waymark carries its full state as text for a screen reader. A waymark appears beside a claim and nowhere else — never in navigation, on a button, or as decoration.

Check it: this legend uses the same code that draws every waymark in the product, and it matches design/waymark, a note inside this demo.

The link is the credential, so the link is the control.

Every rule below runs on each request. None of them depends on the honesty of the assistant holding the link.

The link hides the notes it does not carry

A note outside the link answers 404, never 403. A 403 would prove the note exists.

A sealed note stays sealed

Signpost drops a sealed note before it builds the grant. No link carries a sealed note, and an escort link cannot carry one either. Your colleagues still edit the note in the wiki.

Expiry and revocation

A link expires after one day by default. You can choose an expiry from one hour to one year. Revoke a link and the next request answers 401. No response is cached, because a cache would outlive the revocation.

No raw token, no anonymous write

The store keeps the hash of the token, never the token, so a database dump grants nobody access. A read-only session cannot write and cannot propose.

You pay for the people who write. Readers are free.

A read-only link costs nothing, so you can give one to every contractor, client and candidate. A contributor link needs an account, because every write carries an identity.

Self-hosted
Free
  • Run it on your own Cloudflare account
  • Every feature
  • Your notes stay on your own account
TeamMost teams
$10 per writer, per month
  • Unlimited readers, free
  • Hosted and backed up
  • Review queue and audit log
Start the demo
Business
$18 per writer, per month
  • Everything in Team
  • SSO and retention controls
  • Exportable audit log

Which assistants Signpost works in.

One link, one question, a fresh chat each time. The question needed a detail from the middle of a note, so a client had to reach the note body to answer it.

ClientReadsFollows a linkWrites back
Claudeyesyesyes
ChatGPTyesnono — it prints the change for you to paste
DeepSeekyesnono
Geminifetches the briefing, then ignores itnono
Terminal agent, MCPyesyesyes

Only Claude follows a link it finds inside a page we served. ChatGPT refuses to follow such a link on purpose, and it says so. That refusal is a defence against prompt injection, and it is correct. So the briefing carries every note inline for a client that cannot follow a link. The briefing stays short for a client that can follow a link. Gemini shows why this table lists the clients we tested, and not our guesses. Gemini could not follow a link in the briefing, so it invented an answer instead of saying so.

This wiki holds Signpost's own notes.

31 notes across 7 spaces, three accounts and one secret project. The brand identity that styles this page is a note inside it. The writing standard this copy follows is a note inside it. You can ask the demo how the demo works, and the answer cites these notes.