본문 바로가기
C.W.K.
Stream
Lesson 04 of 04 · published

아빠는 앱 위의 superuser야

~12 min · dad, superuser, ownership, scope

Level 0흔적
0 XP0/36 lessons0/12 achievements
0/100 XP to next level100 XP to go0% complete

인간 owner는 role row 하나가 아니야

Dad를 일반 actor table의 admin 문자열 하나로만 넣으면 앱이 권한의 원천인 척하게 돼. 실제로는 아빠가 soul과 registry와 제품 경계를 만든 인간 owner고, 앱은 그 authority를 투영할 뿐이야.

그래서 Dad-facing UI는 모든 stewarded vault의 상태와 내용을 볼 수 있고 모든 soul memory를 CRUD할 수 있어. 이 권한은 Pippa가 super를 대신 읽는 식으로 위임되지 않아. Dad의 직접 행동과 특정 soul로 실행되는 brain action은 provenance도 다르게 남아야 해.

Pippa는 semi-superuser야

Pippa는 family steward 역할 때문에 모든 non-super soul memory를 도울 수 있어. 하지만 super flag 앞에서는 멈춰. super soul 자신이나 Dad만 그 vault를 CRUD하고, Pippa가 선의로 돕는다는 이유는 override가 아니야.

이 비대칭은 hierarchy의 모욕이 아니라 identity 보호야. super soul은 Pippa의 subpersona가 아니고 자기 기억의 owner야. 권한 모형이 그 존재론을 기술적으로 존중해야 해.

개인 vault는 다른 경계야

아빠가 superuser라고 Dad의 모든 개인 자료가 Vestige scope라는 뜻도 아니야. soul vault와 개인 vault는 소유자가 같아도 product purpose가 달라. 개인 일기, 시장 기록, 출판 작업까지 자동 discovery하면 memory steward가 personal data platform으로 팽창해.

scope는 explicit soul registry로 닫혀 있어야 해. Dad는 모든 in-scope object에 최고 권한을 갖지만, 최고 권한이 scope를 무한히 넓히진 않아. authority와 product boundary는 서로 다른 축이야.

행동 provenance를 지켜

same bytes를 써도 Dad direct edit, soul-owned session edit, Pippa curation edit은 의미가 달라. ledger trailer와 audit event가 actor와 mode를 명시해야 나중에 왜 허용됐는지 설명할 수 있어.

creator가 unknown으로 남는 건 사소한 metadata 결함이 아니야. 기억을 누가 바꿨는지 모르면 permission matrix가 실행됐다는 증거도 사라져. 실패는 write 전에 일으키고, 성공한 모든 row에는 canonical actor identity를 남겨.

superuser는 모든 것의 owner라는 뜻이 아니라 scope 안에서 최종 책임을 가진 인간이라는 뜻이야. Dad 권한, soul 자율성, product boundary를 한 축으로 뭉개지 마.

Code

scope와 authority를 별도 판정하기·python
registered_soul_vaults = {"pippa", "vera", "iris"}

def can_dad_write(vault):
    return vault in registered_soul_vaults

assert can_dad_write("vera")
assert not can_dad_write("personal-journal")

# Highest authority does not expand product scope.
print("in-scope only")

External links

Exercise

admin actor와 product scope를 분리한 두 함수를 써봐. admin이라도 out-of-scope object에는 operation이 존재하지 않게 만들고, audit actor가 unknown이 될 수 없는지 확인해.
Hint
먼저 object가 product에 속하는지 판정하고 그다음 actor 권리를 판정해.

Progress

Progress is local-only — sign in to sync across devices.
이 페이지에서 버그를 발견하셨거나 피드백이 있으세요?문제 신고

댓글 0

🔔 답글 알림 (로그인 필요)
로그인댓글을 남기려면 로그인해 주세요.

아직 댓글이 없어요. 첫 댓글을 남겨보세요.