Scope: repository state or decisions that admit, deny, hide, narrow, revoke, or expose a user operation or row. Transport-only integrity checks are included when token/session possession is the gate; ordinary workflow booleans such as isRead, job leases, and UI expansion state are excluded. “Authoritative” means the server or PostgreSQL path enforces the decision. “Advisory” means client projection, navigation, or tool exposure is rechecked elsewhere. This is an inventory of the current model, not a proposed replacement.
| name | layer (platform/server/membership/grant/channel/audience) | type | who writes | who reads | what it actually gates | file:line |
|---|---|---|---|---|---|---|
users.account_status |
platform | persisted enum: active, disabled, banned |
Account lifecycle/support execution; GDPR execution sets disabled; fixtures and migrations seed it |
Channel/server calculators, auth/read models, notifications, media, searc |