Skip to content

DL-363

Writing a tenant-scoped user-secret row requires an admin (store.UserRoleAdmin, go/internal/store/types.go), reusing the existing role elevation rather than introducing a permission concept: tenant (0) admin-only, user (1) and agent (2) writable by the owning user or an admin. SUPERSEDED IN PART by DL-370: the role check lands at the RPC edge, not the store door, which keeps DL-360’s scope-shape and referential checks. READS are deliberately asymmetric — a plain user’s agent resolves tenant rows, which is the point of a shared tenant value under DL-361; reading a shared secret is the feature, writing one is the privileged act. The wire surface is now ruled by DL-370 (a SecretScope selector on SetSecretRequest/DeleteSecretRequest)

Status: Active (Matt, 2026-09-12)

Record: ../../server/compass-user-secret-store.md#resolved-decisions