Skip to content

Design: does approver routing imply record read visibility? (#7345 model half) #7497

Description

@claude

Restart-when: the v18 design programme opens — this card enters it carrying the pre-recorded direction preference (route-time explicit record-share grant over an implicit approver-scoped read in the RLS/sharing model)

Split out of #7345 per the maintainer ruling of 2026-08-11: the short-term half (honest inbox UI state when the record is not visible) is queued on #7345 itself; this card holds the security-model question, deliberately NOT ruled quickly.

The gap: approver resolution routes on positions; record visibility is a separate RLS/sharing gate; nothing reconciles the two, so a routed approver can be unable to open the record their request concerns (measured on #7345, server answer 404 RECORD_NOT_FOUND).

Candidate directions (none chosen): a route-time read grant (record-share minted when the request is routed), an approver-scoped read in the sharing model, or status-quo plus honest UI (already queued). Each expands or reshapes the security model differently — needs a design pass, not a one-liner. Explicitly not v17.

Filed by the triage seat Routine (#5474 pilot) recording a maintainer ruling of 2026-08-11. Unassigned — recording, not claiming.


Generated by Claude Code

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions