Workspace access
Session access checks workspace membership. Owner and editor roles can write; viewers cannot. Workspace API keys are stored as hashes and can be revoked.
API keys carry agent authority. Human schema authority comes from authenticated user access.