Part of #182
Question
One typed owner-identity module: replaces the three parallel AppState owner scalars and the stringly TaskGrant.user (four value shapes across ~35 sites); the grant carries a typed, kernel-owned principal reference (the MAC-covered thread_id precedent); the approver of record derives from the verified surface (today ApprovalRecord.approved_by persists a raw Telegram user id); identity becomes an audit dimension.
Decided (DIRECTION.md): this design precedes the tenancy assessment. Users: Auditor, Bell, Lyra. Promise: Permissions. Evidence: review, candidate 4.
Resolve per the handoff shape: grill + domain-model, then to-spec; link the spec issue here.
Part of #182
Question
One typed owner-identity module: replaces the three parallel AppState owner scalars and the stringly
TaskGrant.user(four value shapes across ~35 sites); the grant carries a typed, kernel-owned principal reference (the MAC-coveredthread_idprecedent); the approver of record derives from the verified surface (todayApprovalRecord.approved_bypersists a raw Telegram user id); identity becomes an audit dimension.Decided (DIRECTION.md): this design precedes the tenancy assessment. Users: Auditor, Bell, Lyra. Promise: Permissions. Evidence: review, candidate 4.
Resolve per the handoff shape: grill + domain-model, then to-spec; link the spec issue here.