Four gaps off the coverage map, written for the in-app assistant:
- file-viewer.md — what each kind renders to, the live reload, editing a
Markdown file and the conflict banner, git history mode, and why a `.tex`
must be shown instead of a PDF built from it.
- tasks-page.md — the four sections, disable-vs-delete, where each kind's
result lands, and that there is no "new task" button because tasks are
created in conversation.
- profile.md — display name, language, password, and what an encrypted
account means when the password is forgotten.
- users.md — creating a member and the irreversible encryption choice, the
directory profile that feeds the agents' prompt, deactivating vs deleting,
and the per-person event-triage interval.
Indexed in docs/index.md, cross-linked from files.md, tasks.md and access.md.
The grant junctions (plugin_access, mcp_global_access, mcp_catalog_access)
stay deny-by-default internally, but the rows are written for you at two
moments and never again:
— an object is CREATED: PluginManager::update_config (first toggle —
the plugins row's birth), mcp::catalog_upsert, marketplace install,
mcp::global_enable
— a user is CREATED: UserManager::register_user
Who is included is the role attrs.auto_grant flag (default true, so every
role predating the attribute behaves like an adult member). The seeded
Children preset sets it to false, which is the whole reason the attribute
exists. Admins are skipped because they hold everything implicitly. The
role editor now exposes the switch as a checkbox.
New crate module: db::access_defaults (seed_new_object, seed_new_user,
set_grant_by_default). Additive columns: grant_by_default on plugins,
mcp_catalog, mcp_global_servers (INTEGER NOT NULL DEFAULT 1).
On the frontend the Roles page gets a "New extensions" column and
checklist; the user's plugin/connector rosters are unchanged. i18n:
en, fr, it.
Docs: new docs/access.md for the assistant, plus index.md cross-link.
CLAUDE.md updated with a full default-access section.