diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index e511b0e..51363f4 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -360,9 +360,16 @@ it, and the beds that need a mesh living on NATS can finally run. - [ ] 4.2 a build source's change reaches the builder over the bus, and the build that follows is the one the change asked for - [ ] 4.3 an installation completes over the bus, with the same outcome as the path it replaces -- [ ] 4.4 a person's client: the account, the client that speaks the bus, and the tool surface over - it (design 25 ยง7) โ€” a module's tool invoked from another node and from a person, refused from - an account that may not +- [~] 4.4 a person's client โ€” **the account is done**: a person is not a module and holds no + seat, so their authority is a list of tools (or `*` for an administrator) and nothing else. + Held to four properties, each a way of being wrong that would not announce itself: nothing + but tools, so a person cannot claim a module said something; no ack subject, because + authority over a consumer that does not exist is authority nobody audits; no ability to + answer, because a person who can answer a request is impersonating a module on a bus where + anyone may serve a tool; and two people do not share an inbox. + + Still to build: the client program itself โ€” the command line and the MCP surface over it. + It needs nothing from the consume side, so it is not blocked by step 3. - [ ] 4.5 reports and catch-up: a node that was unreachable catches up rather than losing them **Done when.** Each converted flow is proved against the behaviour it replaced, and the full genesis