Question
How do Accounts, Organization memberships, Host Administrator and Organization Operator permissions, and Organization-scoped Roles assigned to Client Principals compose; which permissions can target Host Source Definitions and their Organization-scoped Capability Source instances, database-defined and project-defined Capability Sources, Source Items, protocol actions, project source declaration, outbound hosts and Source Kinds, Project Configuration Snapshots, Project Contexts, host-owned, Organization-owned, and Account-owned Source Credentials, Secret Requirements, and Secret Grants; how do defaults and deny rules compose; and how do policy or membership changes affect discovery, invocation, context renewal, Surface Revisions, audit evidence, automated clients, and the local stdio principal?
Question
How do Accounts, Organization memberships, Host Administrator and Organization Operator permissions, and Organization-scoped Roles assigned to Client Principals compose; which permissions can target Host Source Definitions and their Organization-scoped Capability Source instances, database-defined and project-defined Capability Sources, Source Items, protocol actions, project source declaration, outbound hosts and Source Kinds, Project Configuration Snapshots, Project Contexts, host-owned, Organization-owned, and Account-owned Source Credentials, Secret Requirements, and Secret Grants; how do defaults and deny rules compose; and how do policy or membership changes affect discovery, invocation, context renewal, Surface Revisions, audit evidence, automated clients, and the local stdio principal?