LensReading which lens this session carries.

Refused by the page register

Identity and tenancy is closed to this session

/identity carries a declared floor of Function Leader. No session is signed in, so no role is held at all and the floor cannot be cleared. This is the whole rule, stated here so that it does not have to be discovered by trial.

PAGE-FLOOR

what this page does

Identity

The page names who may sign in and which tenant they belong to.

declared floor

Function Leader

The same floor is held on POST /api/tenancy/probe, so the control and the page it lives on refuse at the same line.

what this session holds

No session

Signing in is what produces a role. Until then there is nothing to compare with the floor.

Why this route carries a floor

Taken word for word from the page register, which is published in the open.

The page names every account that may sign in, the role the directory gives it, the tenant it belongs to, and where the boundary between the live estate and the sandbox sits. It also carries the tenant probe, whose endpoint was already floored at the function leader. An account roster is the one read on this platform that is worth more to somebody who should not have it than to somebody who should.

What to do about it

Sign in and the role is read from the account record. If the account behind it still sits below the floor, this same screen appears again with the role named.