Whoever holds a role, the engine acts on the ledger only as the venue. An outside party’s role lets it read its own records or hand data to the venue; it never signs for that party, which acts on its own node or wallet. A bearer’s roles claim names the caller’s roles by slug, and each route admits the roles its page names. Your identity provider decides who holds each role. In the access tables, R reads; W writes alone; M makes a four-eyes write, which runs once an approver approves it; A approves four-eyes writes (POST /v1/approvals/{actionKey}:approve); own: an investor reaches only its own holder’s records.

The venue’s own staff

The venue’s own systems

Outside parties working with the venue

Public routes need no bearer and admit anyone: GET /v1/tenants/{tenantId}, GET /v1/health, GET /v1/openapi.json. Related: Conventions · Duties and governance · Deployment patterns