app v3.5 · walkthrough v2 · SPEC-address-custody-v1 · RCTX-979 · rulings applied

Address custody — the full loop

Strict scoping is now the ruling (v1's blend toggle is gone): every view renders exactly one workspace's contract-consistent world. The connective tissue is the bell — org-tagged, each item a guided switch — plus one-tap Home. New in v2: pass an object between your joined workspaces and watch the timeline carry provenance across the wall, visible from both sides. Data crosses org walls only as a relay.

Workspace
flip: [ / ] cycle workspaces · 1 2 3 jump · h home · b bell · j/k walk relays · t timeline · p pass

Email addresses · workspace mapping

The routing key: one address ↔ one membership. Drives claim custody, outbound send-as, and workspace notification routing. Security notices always go to the primary regardless of these mappings.

1:1 enforced — rebinding steals the mapping. Primary is locked (it anchors recovery and security notices).

Claim simulator

Claims file by addressed workspace, with the governance fallbacks. Each claim lands in the list, starts a timeline, and rings the bell in its custodial context.

Relays

Strict scope: exactly this workspace's custodial objects, rendered under its features and contract. Timeline opens provenance; Pass → relays a copy across a wall (policy-checked, recorded on both timelines).

What to verify by feel: ① claim to your work address while sitting in Personal — the bell rings with a guided switch instead of the object appearing here; ② pass the audit from Execution Space to Personal — both objects' timelines record the crossing (who, from where, policy check), and the receiving side shows origin provenance it can see without seeing into the source workspace; ③ ⌂ always lands you Home. Rules: crossing = a relay event checked against the source org's sharing/contract terms; timelines show each side its own lawful view of the chain; custody and region never change retroactively.