Effective-privileges invariant — provenance & replay failure modes

Reference diagram with a chat/text path and a privileged server path. It highlights an invariant: effective privileges must come from server authorization and authoritative state. Failure modes include chat-derived context influencing effective privileges and model output being persisted and replayed into later context.
Effective-privileges invariant — provenance & replay failure modes (reference model).

Overview

A reference model that separates:

Focus: two failure modes where provenance boundaries blur and text-derived artifacts influence privilege-bearing decisions.

Text alternative (long description)

Scope and limitations