DL-362
The canonical user-secret AAD is the five-field tuple "compass/user-secret/v1\x00" + tenantID + "\x00" + decimal(scopeKind) + "\x00" + scopeID + "\x00" + name + "\x00" + decimal(keyVersion) (Go: UserSecretAAD(tenantID string, scopeKind int16, scopeID, name string, keyVersion int16) []byte; SMALLINTs rendered strconv.FormatInt(int64(v), 10)), every field bound unconditionally (a tenant row binds scopeID as the empty string) with \x00 separators keeping the encoding injective. Fixed BEFORE any migration ships because the AAD is baked into every ciphertext — a scope field added later would force a re-encrypt of every row. Refines DL-351’s four-field AAD clause; DL-351’s other rulings stand
Status: Active (Matt, 2026-09-11)
Record: ../../server/compass-user-secret-store.md#a9–scope-model-tenant–user–agent-most-specific-wins