DL-083
Session-transcript credential/storage posture: a full-bucket S3 credential is acceptable for solo/self-host v1 (Garage, single trust domain) despite the stated cross-agent read/tamper threat; real/multi-user deployments use Cloudflare R2 with prefix-scoped tokens so each agent is confined to its own sessions/<session_id>/ prefix. The S3 backend is endpoint-agnostic via COMPASS_S3_ENDPOINT (generic Bun.S3Client), so the hardening is config not a new build; the threat is stated and a hardening follow-up is filed
Status: Superseded by DL-084 (Matt, 2026-07-31)