DUNIN7 · LOOMWORKS · RECORD
record.dunin7.com
Status Current
Path session-handoffs/loomworks-ova-reach-enforcement-scoping-handoff-v0_1.html

Loomworks — OVA reach enforcement — scoping arc handoff — v0.1

Version. 0.1
Date. 2026-07-28
Status. Fresh-chat scoping handoff. Hands to a new Claude.ai scoping session. Commissioned by the Operator 2026-07-28.
Author. Claude.ai. Operator: Marvin Percival.
Grounding. Canonical seed v0.12 (Memory section, reach and contribution axes); loomworks-vertical-vc-diligence-cc-inspection-report-v0_1 (V1, engine main 1aac815); loomworks-foray-ova-integration-strategy-investigation-v0_1; current-status manifest v0.72 or higher — the scoping chat reads the highest version actually present, per document-authority discipline.

Plain-language summary

What this hands off. A scoping arc for making restricted reach real: today, anyone who is a member of an engagement can read all of it, and the seed says that is the temporary state — restriction is committed, the seam is declared, OVA is not yet enforcing. This arc scopes the enforcement.

Why now. Two commercial motions depend on it. The venture diligence vertical needs external people — founders, references, interviewees — who contribute to a deal's record without reading the rest of it. The FORAY-as-term-sheet-condition motion (Appendix A of the inspection report, its own investigation to follow this arc) needs the same shape at larger scale: the target contributes, the investor reads.

What decision the arc produces. A scoping note answering the central design question below, plus a Step 0 inspection brief for Claude Code. It does not produce a change request; that follows the scoping note per the standing two-step.


1. What the seed commits, verbatim posture

The seed's Memory section carries two independent access axes:

Reach (read). A scope is open by default — reachable by any engagement, any Operator. A scope becomes restricted when an access-control list is established on it through OVA; from then OVA governs who may reach it. Restriction is a deliberate, recorded act, not a default. While OVA is not yet enforcing, every scope is effectively open; the access mode is declared and the seam is in place.

Contribution (write). An engagement's own contributors write into it. For shared scopes, a trusted core writes directly and outside contributions are held until admitted. Reach and contribution are independent.

The posture is committed. The mechanism is deliberately deferred — which is what this arc picks up.

2. The engine-side truth, from the inspection

At engine main 1aac815:

  • No read endpoint consults designations. get_resolved_actor grants read on membership existence alone (deps.py:1160-1179); can_commit layers write on top of that. Write is a strict superset of read; there is no read-side check to configure.
  • Adding a designation string to ALLOWED_DESIGNATIONS would be inert on the read side.
  • The Manifestation and Memory-status read surfaces gate on get_contributing_contributor — contributor-flavoured — so those surfaces currently lean toward granting read to exactly the population a restricted engagement would withhold it from.

This is not drift. It is the accurate engine state of "OVA not yet enforcing." The arc's job is to change that state in the direction the seed already names.

3. The central design question

Can a reach access-control list exclude an engagement's own contributor from reading the engagement they contribute to?

The seed's reach axis is scope-level, and it is silent on sub-membership granularity. The engine currently assumes the opposite (membership implies read). Both commercial motions require the answer to be yes for at least one participation shape: the external reference who writes into the record, is held-until-admitted on the contribution axis, and reads nothing.

The scoping chat should treat this as the load-bearing question and resolve it against the seed before touching mechanism. Candidate resolutions to weigh, not prejudge:

  • Reach ACL below membership. The ACL can name a subset of members. Membership grants participation; reach is a separate grant. Cleanest fit to "reach and contribution are independent," largest change to the engine's current assumption.
  • A participation shape that is not membership. External contributors enter through the held-contribution gate without becoming members at all; the read question then never arises for them. Smaller engine delta on the read side, but it must square with the seed's "an engagement's own contributors write into it" and with how held contributions carry attribution for a non-member.
  • A hybrid. Membership implies reach (the engine's current assumption, ratified); non-members contribute through the held gate. This is the smallest build, and the scoping chat should say plainly whether it satisfies the two motions or quietly under-delivers them.

If the resolution amends the seed (any of the three could), the arc surfaces that to the Operator per the standing rule — name the commitment, name the proposal, name the conflict — rather than absorbing it.

4. What the arc must also cover

  • Where enforcement lives. OVA governs the ACL; the enforcement point in the engine must be a chokepoint every read traverses, for the same reason FORAY fires at the substrate — a guarantee in a replaceable surface is not a guarantee. The scoping note names the chokepoint candidates from live code, via the Step 0 brief.
  • The contributor-flavoured read surfaces. The inspection's finding on Manifestation and Memory-status reads (get_contributing_contributor) is in scope: whatever shape wins, those surfaces must not leak to the withheld population.
  • The declared-but-inert seam. The seed says the access mode is declared and the seam is in place. The Step 0 brief verifies what "declared" and "seam" concretely are in the schema today — an access-mode column, an ACL table, nothing — before the scoping note assumes either.
  • Relation to OVA's identity and authorisation machinery per the filed FORAY/OVA integration investigation, so this arc lands as OVA enforcement and not a parallel bespoke ACL that OVA later displaces.
  • What the venture diligence vertical minimally needs versus the full enforcement. If a bounded first slice serves the vertical while full OVA enforcement follows, the scoping note says so and sizes both.

5. What the arc does not do

It does not draft the change request — the scoping note and Step 0 brief come first, per the standing two-step. It does not build. It does not develop the FORAY-as-term-sheet-condition motion; that investigation is separately commissioned and sequenced after this arc so it can cite the enforcement shape rather than assume it. It does not amend the seed itself; it surfaces any amendment need to the Operator.

6. Session protocol for the scoping chat

  1. Read the highest-versioned current-status manifest actually present in loomworks-record, then seed v0.12 (or higher if present), then the inspection report's V1 section, then the FORAY/OVA integration investigation. In that order.
  2. Draft the Step 0 inspection brief for Claude Code covering Section 4's verification points; halt for Operator hand-off to CC.
  3. On CC's evidence, draft the scoping note: the central question resolved or presented as a bounded Operator decision, mechanism candidates sized, seed-amendment need named if any.
  4. Standard formats: scoping note and this arc's documents HTML primary with Markdown source; the Step 0 brief Markdown primary. Versioned filenames throughout. All documents land in loomworks-record.

DUNIN7 — Done In Seven LLC — Miami, Florida
Loomworks — OVA reach enforcement — scoping arc handoff — v0.1 — 2026-07-28