Skip to content
SkyKeephelp

Surfaces shaped by what an account can reach

The vault has always held that an administrator belongs to no compartment

and can therefore read no document, and the delegated compartment

administrator — the clientadmin — is built the same way on purpose, because

an account able to merge compartments and also read them could quietly

merge its way into anything. So the vault does not offer either of them

what it would refuse: the page says plainly why there is no upload form

and no query box, the API refuses the same request for the same reason,

and the refusal is recorded. The reason

names only the caller's own account, which the vault will tell them anyway

if they ask, and never anything about what the vault holds. For an ordinary

member nothing changes at all — the same form, the same pipeline, the same

gates, the same refusals.

The vault refuses before the ingest pipeline is ever reached

The refusal names the caller's own account and nothing else

An ordinary member's upload is untouched by any of this

An administrator is told why the upload form is not therestack

A delegated compartment administrator is refused a querystack

The portal page carries the wording that stands where a form wouldstack