Fields have explicit treatment
Every field is allowed, denied or placed behind owner approval. Missing fields default to no access.
The lab keeps task access in a versioned YAML manifest that people can read and tests can enforce.
Every field is allowed, denied or placed behind owner approval. Missing fields default to no access.
Read count, expiry, output destination and memory treatment belong to the policy rather than to a model prompt.
A receipt identifies the exact policy version. A newer decision cannot silently rewrite an older task history.