Split Security & Entitlements into Access Control + Security Separate the combined Concepts page into two: - Access Control (Architect) - client authentication, entitlements (authorization), and transitive entitlement for derived content. New lead. Placed after Architecture: Basics in the sidebar. - Security (Architect, Operator) - the operational surfaces: REST/admin access, cluster-internal traffic, transport, and deployment secrets. Keeps the original "Elastic MDS's security..." lead, adapted. Placed after Architecture: Advanced. Drops the "security surfaces" list; re-points all cross-references (Glossary, Entitlements-Context, Configuration-Advanced, How-to-Read to Access Control; Deployment-Advanced, API-Token-Administration, REST-API to Security). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Security: give transitive derived-content entitlement its own section The transitive property (read access to derived content requires access to every input, transitively - no laundering via computed columns/views) is a significant guarantee; pull it out of the framework list into its own prominent section. Add a one-way pointer from Entitlements Context to this architecture section. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
Review edits: Develop-JMS entitlements intro (no S&E, no conflation) + STREAM_UPDATE; Entitlements page use-case framing (self=own identity, proxy=on behalf of end-user) + drop S&E link; Conventions: CORRECTION/RESET marked unused + moved down, expanded multi-stream from guide 5.4
Draft Dynamic Data Conventions (message types, stream state, header properties, multi-stream) and Entitlements Context (comma-delimited context, self/proxy + code-based use-cases, status-only); sidebar + Develop-JMS entitlements link