seatChannelPolicy<TSeat extends ModelPreference> function

AgentPermissionPolicy seatChannelPolicy<TSeat extends ModelPreference>(
  1. TreeContext context, {
  2. required String seatId,
})

The station permission policy in effect for ONE capability's channel, keyed by the seat's own preference type TSeat and stamped with seatId.

Total, in strict precedence:

  1. an EXPLICITLY mounted AgentPermissionPolicy wins outright, returned unchanged - including AgentPermissionPolicy.unavailable, which is how a station locks a subtree down over an armed seat;
  2. else, an ARMED exact TSeat is the channel's admitted identity, so it derives AgentPermissionPolicy.trustedHeadless under seatId;
  3. else AgentPermissionPolicy.unavailable - a channel with no seat identity authorizes nothing.

THE IDENTITY IS THE EXACT TYPE (ADR-0006 D2: the TYPE is the scope), read from the InheritedSeed the seat's own provider() seed mounts. The GENERIC ModelPreference is deliberately NOT consulted: it is the station's shared model default, not an arming of this seat, and treating it as an identity would hand a grant to any channel that inherited a default. Nothing here reads a name, a runtime type, an environment's availability, or the model-spend axis - a permission is not a spend.

THE EFFECT VERB (getInheritedSeedOfExactType), per ADR-0008 D3: both callers are createSession edges, not builds.

Implementation

AgentPermissionPolicy seatChannelPolicy<TSeat extends ModelPreference>(
  TreeContext context, {
  required String seatId,
}) {
  final explicit = context.getInheritedSeedOfExactType<AgentPermissionPolicy>();
  if (explicit != null) return explicit;
  final seat = context.getInheritedSeedOfExactType<TSeat>();
  if (seat == null) return const AgentPermissionPolicy.unavailable();
  return AgentPermissionPolicy.trustedHeadless(id: seatId);
}