Skip to content

DL-360

User secrets are scoped at THREE levels — tenant (0), user (1), agent (2) — via scope_kind SMALLINT + scope_id TEXT (empty string for a tenant row, the owning accounts.id for user/agent rows) with the secrets PK widened to (name, scope_kind, scope_id); a tenant row is a real shared VALUE several users resolve, not a declaration placeholder. The scope↔id shape is CHECK-enforced (secrets_scope_shape); scope_id carries NO FK to accounts — a tenant row’s '' can never satisfy one and Postgres has no conditional FK — so user/agent referential integrity is enforced at the store door in the writing transaction

Status: Active (Matt, 2026-09-11)

Record: ../../server/compass-user-secret-store.md#a9–scope-model-tenant–user–agent-most-specific-wins