Skip to content

DL-361

Secret resolution is most-specific-wins — agent > user > tenant, ONE value per name in the injected environment — collapsed in SQL (DISTINCT ON ordered by scope_kind DESC, the numeric encoding being the precedence) so shadowed rows never leave Postgres or get decrypted; FetchSecrets resolves per agent account using the identity the runnerhub authz maps (sessionAccounts/containerAccounts) already hold and previously discarded, the user tier reached through the single agent_accounts.owner_user_id FK hop. Scope is an ADDITIONAL filter inside a tenant — RLS tenant isolation stays the outer boundary, never replaced. SUPERSEDED IN PART by DL-370: the SetSecret/DeleteSecret verbs no longer pin to the tenant coordinate — they carry an explicit scope selector defaulting to user scope

Status: Active (Matt, 2026-09-11)

Record: ../../server/compass-user-secret-store.md#a9–scope-model-tenant–user–agent-most-specific-wins