2026-09-23·by Sijie Wang#standmeet#architecture#design

access-control-diagram-coverage

Parent: access-control

The pillar's class diagrams live on the design pages they belong to; this page is the coverage gate.

type / areadiagrammed atverified
RoleSnapshot (all 18 fields + methods), RoleSnapshotInitrole-snapshot-frozen✓ code
capability_settings (the live layer)role-snapshot-frozen✓ schema
owner_keypairs (incl. last_used_ip / last_used_user_agent) + CreateKeypair / VerifySigv1owner-keypair-auth✓ code
access_codes columns (incl. ghosts jsonb, quota fields, slug, inline_prompt)ER on access-control; ☐ no class diagram✓ schema
code_capability_denials / code_skill_denials / code_corpus_denialsER on access-control✓ schema
embeds (key_id / public_key) + VerifyEmbedTokenembed-credential-never-carries-the-code (prose)☐ no class diagram
quota enforcement types☐ not yet diagrammed
BYOAI envelope typesbyoai-envelope (prose)☐ no class diagram
_meta session scope shape (trusted identity)trusted-identity-via-meta (prose)☐ no class diagram

The ☐ rows are the debt list — promote by adding the class view on the owning page and updating this table.

about this entry

One of sijie's wiki entries. The AI on this site is grounded in the same corpus and answers in sijie's voice, with citations back to entries like this one — answering costs sijie money, so it waits behind a code: enter an access code →