Parent: access-control
The pillar's class diagrams live on the design pages they belong to; this page is the coverage gate.
| type / area | diagrammed at | verified |
|---|---|---|
| RoleSnapshot (all 18 fields + methods), RoleSnapshotInit | role-snapshot-frozen | ✓ code |
| capability_settings (the live layer) | role-snapshot-frozen | ✓ schema |
owner_keypairs (incl. last_used_ip / last_used_user_agent) + CreateKeypair / VerifySigv1 | owner-keypair-auth | ✓ code |
access_codes columns (incl. ghosts jsonb, quota fields, slug, inline_prompt) | ER on access-control; ☐ no class diagram | ✓ schema |
| code_capability_denials / code_skill_denials / code_corpus_denials | ER on access-control | ✓ schema |
embeds (key_id / public_key) + VerifyEmbedToken | embed-credential-never-carries-the-code (prose) | ☐ no class diagram |
| quota enforcement types | ☐ not yet diagrammed | — |
| BYOAI envelope types | byoai-envelope (prose) | ☐ no class diagram |
_meta session scope shape (trusted identity) | trusted-identity-via-meta (prose) | ☐ no class diagram |
The ☐ rows are the debt list — promote by adding the class view on the owning page and updating this table.