Skip to content

DL-370

SetSecretRequest/DeleteSecretRequest gain a SecretScope scope selector, and the default is USER scope — an unspecified scope writes (scope_kind=1, scope_id=caller), so a client that omits the field gets the private-by-default coordinate rather than a tenant-wide value every other user’s agents resolve. Tenant scope is explicit and requires store.UserRoleAdmin, checked at the RPC edge (where requireUser’s existing GetAccount already holds the role) rather than the store door, which keeps DL-360’s scope-shape and referential checks. Agent scope gets no wire surface: agents hold no write door, so an agent-scoped write has no authenticated writer to authorize. SUPERSEDES DL-361’s “pinned to the tenant coordinate” clause and DL-363’s enforcement point, keeping DL-363’s authorization matrix. Corrects a factual error in D8: no admin check existed on the user-secret write path — classifyProcedure returns authenticatedOpen for both verbs — so T5 adds the gate rather than documenting one. Behavior change stated not silent: today’s tenant-wide rows become per-user on re-set

Status: Active (Matt, 2026-09-12)

Record: ../../server/compass-user-secret-store.md#resolved-decisions