Skip to content

Design the typed owner identity #188

Description

@George-RD

Part of #182

Question

One typed owner-identity module: replaces the three parallel AppState owner scalars and the stringly TaskGrant.user (four value shapes across ~35 sites); the grant carries a typed, kernel-owned principal reference (the MAC-covered thread_id precedent); the approver of record derives from the verified surface (today ApprovalRecord.approved_by persists a raw Telegram user id); identity becomes an audit dimension.

Decided (DIRECTION.md): this design precedes the tenancy assessment. Users: Auditor, Bell, Lyra. Promise: Permissions. Evidence: review, candidate 4.

Resolve per the handoff shape: grill + domain-model, then to-spec; link the spec issue here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions