How Cumae Access Policies Work
Why a record needs more than one setting
A public identity record and a distributor price list are both business information, but they do not belong in the same place. Publishing everything openly gives away terms you negotiated. Publishing nothing openly leaves AI systems to guess.
Access policies resolve that. Each part of your Cumae record carries a policy, so your identity can be readable by anyone while your partner pricing is readable only by the partner it belongs to.
The four policies
Your public identity record. Readable by anyone, including unregistered AI systems and search engines, with no registration required. Company name, canonical website, general description, public location information, general product or service categories, and a link to current authoritative information. Every Cumae record has this layer, including the free Cumae Publish tier.
Your full general Cumae record, available to identified applications that have accepted CRSTBL’s access terms. This is where depth lives: products, menus, services, hours, attributes, prices, availability, warranties, policies, qualifications, and preparation or safety limitations. “Registered” means the application is identifiable and accountable — not anonymous.
A partner-specific view that your business approves individually. Different partners can see different scopes: distributor pricing for one, territory and warranty processes for another. Each gets separate credentials, and one can be suspended without affecting the others.
Restricted information available only to your own company-controlled agents, applications and integrations. Private information is not available to external platform partners under any delivery method.
Most businesses use several at once
These are layers, not tiers. A typical configuration looks like this:
- Identity information stays Open, so search engines and AI assistants can find and describe the business.
- The general record requires Registered access, so the depth is available to identified applications under terms.
- Partner-specific terms are Allowlisted to the individual partner they concern.
- Internal information stays Private, reachable only by the company’s own agents.
Which policies your plan can configure
Access policies are a property of your information, not a plan level — but which ones you can configure depends on the record you hold.
- Cumae Publish (free) carries Open only. The record is self-asserted, publicly accessible, and crawlable by any AI system.
- Cumae Record (paid) adds domain and entity verification, Registered access to the full record, and the ability to configure Allowlisted partner views and Private information.
The tier names and the policy names are deliberately different words. Cumae Publish and Cumae Record describe what a business buys. Open, Registered, Allowlisted and Private describe what a piece of information is readable by.
How this looks from the AI platform’s side
The same four policies, read from the other direction:
- Any AI system can read Open records. No registration, no agreement, nothing to sign.
- Registered platform partners — AI platforms that have entered an agreement with CRSTBL — can access full Registered records, under contractual restrictions on retention, redistribution and model training.
- Allowlisted views go only to partners a participating business has approved individually.
- Private information is not available to external platform partners at all.
No AI system pays to retrieve a record, and payment never affects retrieval, ranking or representation. A free Publish record is exactly as retrievable as a paid one. See Platform Partners.
Delivery method is not access
This is the distinction people miss most often, and it matters commercially as well as technically.
MCP, APIs and data feeds are delivery methods. They describe how information travels. Open, Registered, Allowlisted and Private are authorization policies. They describe what an application is permitted to receive.
Connecting by a particular method does not widen what you can read. An application connected by MCP and an application connected by API see exactly the same information if they hold the same policy, and different information if they do not. CRSTBL confirms both the delivery method and the authorized scope during pilot scoping.
Identifiability is what makes the rest possible
Open access is anonymous by design. A Cumae record logs that its machine surface was fetched, without fingerprinting or storing IP addresses, so an anonymous retrieval cannot be attributed to a particular system.
Registered and allowlisted access is authenticated, so it can be attributed. That difference is why access reporting, scope enforcement and revocation apply to registered applications and not to anonymous readers — and it is a property of the architecture rather than a policy choice.
What a business can do to access it has granted
- Scope it. Restrict by location, product, territory or partner relationship rather than exposing a whole record.
- Log it. Access to Cumae can be logged, including the registered application, the record, the scope and the time of access.
- Downgrade or suspend it. A partner’s access can be narrowed or suspended without affecting any other partner.
- Revoke it. Access can be withdrawn entirely.
One honest limit: CRSTBL can log access to Cumae, but may not be able to observe every downstream use after information has been retrieved. That is why retention, caching, redistribution and model-training rights are also governed contractually rather than technically alone.
Frequently asked questions
Are these the same as pricing tiers?
No. Access policies are a property of your information, not a plan level. Plan determines which policies are available to configure — the free Cumae Publish tier carries Open only, paid records add Registered, and Allowlisted and Private views are configured with CRSTBL. See Cumae pricing.
Can I change a policy after publishing?
Yes. Policies are configuration, not a permanent property of the record. Information can be moved between layers as your business changes what it is willing to publish.
What is a registered application?
An identified AI service or software application that has accepted CRSTBL’s access terms and been authorized to retrieve a full general Cumae record. See Platform Partners.
Does Open access mean anyone can take my full record?
No. Open covers the public identity record only. The full general record requires Registered access, and partner-specific views require individual approval.
Can CRSTBL see what an application does after it retrieves information?
Not entirely. Access to Cumae can be logged, but downstream use after retrieval may not be observable, which is why it is also addressed contractually.
Decide who gets to see what.
Access policies are configured per record and per partner. If you share different information with different business partners, that is a conversation worth having before you publish.