Nothing here yet.
Nothing here yet.
Thanks, Kartik. I'd put the deny at the identity layer: if the action's purpose and the identity grant don't line up, the graph's candidate context shouldn't make the read or send permissible. The runtime should record that decision so the user can see why it stopped. Would you test that as an explicit cross-layer case in the harness?