What this hands off. A scoping arc for making restricted reach real: today, anyone who is a member of an engagement can read all of it, and the seed says that is the temporary state — restriction is committed, the seam is declared, OVA is not yet enforcing. This arc scopes the enforcement.
Why now. Two commercial motions depend on it. The venture diligence vertical needs external people — founders, references, interviewees — who contribute to a deal's record without reading the rest of it. The FORAY-as-term-sheet-condition motion (Appendix A of the inspection report, its own investigation to follow this arc) needs the same shape at larger scale: the target contributes, the investor reads.
What decision the arc produces. A scoping note answering the central design question below, plus a Step 0 inspection brief for Claude Code. It does not produce a change request; that follows the scoping note per the standing two-step.
The seed's Memory section carries two independent access axes:
Reach (read). A scope is open by default — reachable by any engagement, any Operator. A scope becomes restricted when an access-control list is established on it through OVA; from then OVA governs who may reach it. Restriction is a deliberate, recorded act, not a default. While OVA is not yet enforcing, every scope is effectively open; the access mode is declared and the seam is in place.
Contribution (write). An engagement's own contributors write into it. For shared scopes, a trusted core writes directly and outside contributions are held until admitted. Reach and contribution are independent.
The posture is committed. The mechanism is deliberately deferred — which is what this arc picks up.
At engine main 1aac815:
get_resolved_actor grants read on membership existence alone (deps.py:1160-1179); can_commit layers write on top of that. Write is a strict superset of read; there is no read-side check to configure.ALLOWED_DESIGNATIONS would be inert on the read side.get_contributing_contributor — contributor-flavoured — so those surfaces currently lean toward granting read to exactly the population a restricted engagement would withhold it from.This is not drift. It is the accurate engine state of "OVA not yet enforcing." The arc's job is to change that state in the direction the seed already names.
Can a reach access-control list exclude an engagement's own contributor from reading the engagement they contribute to?
The seed's reach axis is scope-level, and it is silent on sub-membership granularity. The engine currently assumes the opposite (membership implies read). Both commercial motions require the answer to be yes for at least one participation shape: the external reference who writes into the record, is held-until-admitted on the contribution axis, and reads nothing.
The scoping chat should treat this as the load-bearing question and resolve it against the seed before touching mechanism. Candidate resolutions to weigh, not prejudge:
If the resolution amends the seed (any of the three could), the arc surfaces that to the Operator per the standing rule — name the commitment, name the proposal, name the conflict — rather than absorbing it.
get_contributing_contributor) is in scope: whatever shape wins, those surfaces must not leak to the withheld population.It does not draft the change request — the scoping note and Step 0 brief come first, per the standing two-step. It does not build. It does not develop the FORAY-as-term-sheet-condition motion; that investigation is separately commissioned and sequenced after this arc so it can cite the enforcement shape rather than assume it. It does not amend the seed itself; it surfaces any amendment need to the Operator.
loomworks-record, then seed v0.12 (or higher if present), then the inspection report's V1 section, then the FORAY/OVA integration investigation. In that order.loomworks-record.