concept Updated 2026-10-06

Notespaces and Endpoints

Where observations live, and the data that makes matches precise.

Every entity has a notespace

Each asset, playbook, and component carries a notespace: one page where its links, notes, and history live. When you open a technology, you are seeing its notespace; when you open an asset, you are seeing the asset's.

Notespaces make the model uniform. A component is not just a tag — it is a full record that assets can link to, that other components can nest inside, and that notes can accumulate against over time.

A link between an asset and a component is not just "this asset has this technology." Each link can carry:

  • Endpoints — where the capability was observed.
  • Scoped children — vectors and quirks nested inside a specific parent component.
  • Requirements — whether a playbook needs it, or just benefits from it.
  • Yield metadata — when a capability was earned, which playbook granted it, and the endpoint it was discovered on.

Why endpoints matter

Endpoints are what turn a pile of components into a theory of the target. A file upload on the marketing site and an SSRF-prone fetcher on the internal API are both "on example.com" — but they only combine if they actually meet at the same endpoint.

The engine uses endpoints for co-location: a rule can require that two capabilities occur on the same endpoint before it counts. The stricter the endpoint data you record, the more trustworthy the match.

Recording endpoints is not optional busywork. A playbook whose primitives were never tied to matching endpoints will not match — and that is by design, because an exploit that assumes two things meet without evidence is a guess.

What's next

Playbooks — the recipes that consume all of this.