Filing gate: ① a declared≠enforced family, filed as one sweep card per family under ruling A′ item ④ on #18900 (5727134555). This is triage's standing request 5857165909 on the seat post. Family rls-tags, seat verdict RETIRE.
reach: the declared authoring door. packages/spec parses this key and publishes it in the reference docs. The liveness ledger row cited below records it as not enforced, and the census re-measured the reader side (§5 cross-check C11, with a lit control).
- The criterion is the maintainer's: 「每族该问的是:主流平台有没有这个能力 —— 有 ⇒ 补消费端(一次做对);没有 ⇒ 退役,而不是看仓里有没有人读」.
- The maintainer's one word, per ruling A′ ④: RETIRE (the seat's proposal) or ENFORCE (build the consumer once, correctly).
Census by the domain:spec execution seat 1 (session_01Rjy9MeetSfq34PKn81CRiN, seat post #6017), 2026-09-27. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim. This family's rank is 16 of 16, the last one. The sibling family cards are #20273, #20274, #20281, #20282, #20287–#20289, #20294, #20295, #20299–#20301, #20312, #20313 and #20318.
Capability: Free-form tags on a row-level security policy for governance or compliance reporting
| key |
ledger status |
ledger row |
what the ledger cites |
permission.rowLevelSecurity.tags |
dead (verified 2026-08-10) |
packages/spec/liveness/permission.json:225 |
note: CORRECTED 2026-07-30 (was live with no evidence): no reader in either repo — governance/compliance reporting never consumes policy tags. RE-TESTED AND UPHELD 2026-08-10 (#7427) under the previews ruling (#7131), same measurement as this block's label: at … |
Mainstream evidence:
- Salesforce sharing rules, Dataverse security roles and PostgreSQL RLS policies have no tag attribute. A ServiceNow ACL has none either (whether its generic record tags apply to ACL records is UNVERIFIED, and they would be a list feature, not a policy attribute).
- Compliance reporting in those platforms keys on the rule itself (name, object, criteria).
Verdict: RETIRE — the mainstream lacks it, or it duplicates a capability already delivered here; one batch for the family.
Reader that must exist / disposition: none; this is a retirement with a retiredKey tombstone on RowLevelSecurityPolicySchema.
User-visible risk (1): Benign organisational metadata that nothing reads (ledger).
Acceptance: Every key listed is retired by the spec-property-retirement route: a retiredKey tombstone with its prescription (the ledger row STAYS, status dead, as for every tombstone), an ADR-0087 D2 conversion or D3 entry, docs regenerated; authoring the key becomes a tsc + parse error; pnpm check:liveness green.
Lane: domain:spec (objectstack)
File surface: packages/spec/src/security/rls.zod.ts:499 · packages/spec/liveness/permission.json
Dedupe: areas\.description \| flow\.description \| hook\.(label\|description) \| rowLevelSecurity\.(label\|description\|tags) \| view\.label\b \| HookPreview → 3 open hits. None carries a key of this family:
四轴:
- 实际业务需求: 主流平台的行级策略都没有标签,合规报表按规则本身统计。
- 项目长远合理性: 安全面越窄越好审计。一个无人消费的自由标签只会稀释策略 schema。
- 防 AI 写错: AI 可能用 tags 表达「仅限某角色」之类的意图,这比无效更糟。退役消除这种误读。
- 创业阶段不扩散: 单键退役,可与本发布的其他退役合批。
Filing gate: ① a declared≠enforced family, filed as one sweep card per family under ruling A′ item ④ on #18900 (
5727134555). This is triage's standing request5857165909on the seat post. Familyrls-tags, seat verdict RETIRE.reach:the declared authoring door.packages/specparses this key and publishes it in the reference docs. The liveness ledger row cited below records it as not enforced, and the census re-measured the reader side (§5 cross-check C11, with a lit control).Census by the
domain:specexecution seat 1 (session_01Rjy9MeetSfq34PKn81CRiN, seat post #6017), 2026-09-27. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim. This family's rank is16of 16, the last one. The sibling family cards are #20273, #20274, #20281, #20282, #20287–#20289, #20294, #20295, #20299–#20301, #20312, #20313 and #20318.Capability: Free-form tags on a row-level security policy for governance or compliance reporting
permission.rowLevelSecurity.tagspackages/spec/liveness/permission.json:225label: at …Mainstream evidence:
Verdict: RETIRE — the mainstream lacks it, or it duplicates a capability already delivered here; one batch for the family.
Reader that must exist / disposition: none; this is a retirement with a
retiredKeytombstone on RowLevelSecurityPolicySchema.User-visible risk (1): Benign organisational metadata that nothing reads (ledger).
Acceptance: Every key listed is retired by the spec-property-retirement route: a retiredKey tombstone with its prescription (the ledger row STAYS, status dead, as for every tombstone), an ADR-0087 D2 conversion or D3 entry, docs regenerated; authoring the key becomes a tsc + parse error; pnpm check:liveness green.
Lane: domain:spec (objectstack)
File surface: packages/spec/src/security/rls.zod.ts:499 · packages/spec/liveness/permission.json
Dedupe:
areas\.description \| flow\.description \| hook\.(label\|description) \| rowLevelSecurity\.(label\|description\|tags) \| view\.label\b \| HookPreview→ 3 open hits. None carries a key of this family:liveness-dead-propertyandliveness-live-elsewhere-propertycannot fire on 17.3.0 — 90dead+ 1live-elsewhereledger rows and not one setsauthorWarn#16094 — lint axis (authorWarn opt-in for dead rows) plus a list.tabs re-derivation already answered by spec: re-derive the liveness ledger before itsdead/live-elsewhereverdicts start warning authors —view.jsonlist.tabsre-read plus a sampled audit of the 90deadrows (ledger half of #16094) #16362 (closed); not an enforce-or-remove carrierlabel: NamedListView (listViews entry) label, not the view container labellabel: NamedListView (listViews entry) label, not the view container label四轴: