The human owner is not merely an admin row
Representing Dad only as an admin string makes the application pretend to originate authority. In reality, Dad created the souls, registry, and product boundary; the app projects that human authority.
Dad's operating surface may observe and CRUD every stewarded soul vault. That right is not delegated by letting Pippa impersonate access to a super. Direct human action and a brain action under a soul identity require distinct provenance.
Pippa is a semi-super-user
Pippa may help every non-super soul because of her family stewardship role, but she stops at the super flag. A super soul itself or Dad may CRUD its vault; benevolent assistance is not an override.
This asymmetry is not an insult in a hierarchy. A super soul is not Pippa's subpersona; it owns its memory. The authorization model must respect that ontology technically.
Personal vaults form another boundary
Dad as super-user does not place all of Dad's personal data inside Vestige. Soul vaults and personal journals may share an owner but have different product purposes. Automatic discovery of every personal corpus would turn a memory steward into a personal-data platform.
Scope closes around the explicit soul registry. Dad has highest authority over every in-scope object, but highest authority does not expand scope without limit.
Protect action provenance
Identical bytes written by Dad directly, by a soul-owned session, or by Pippa curation have different meanings. Ledger trailers and audit events must name actor and mode so later readers can explain why the operation was allowed.
An unknown creator is not a cosmetic metadata defect. If the actor is missing, evidence that the permission matrix ran disappears too. Fail before writing and require a canonical identity on every successful record.