PE9 ★ — the ENTITY PERMISSIONS / RLS concern, proven with TWO REAL IDENTITIES.
Distinct from the unified provider concern: this is set-level CRUD gating driven by
MJ: Entity Permissions and surfaced by EntityInfo.GetUserPermisions. The seeded role-less
principal (it-nogrant@integration.test, zero UserRoles) must have NO Read on an entity the
context user CAN read. Asserting the DIFFERENCE — not the context user's allow — is what makes
this non-vacuous under a high-privilege harness identity.
PE9 ★ — the ENTITY PERMISSIONS / RLS concern, proven with TWO REAL IDENTITIES.
Distinct from the unified provider concern: this is set-level CRUD gating driven by
MJ: Entity Permissionsand surfaced byEntityInfo.GetUserPermisions. The seeded role-less principal (it-nogrant@integration.test, zero UserRoles) must have NO Read on an entity the context user CAN read. Asserting the DIFFERENCE — not the context user's allow — is what makes this non-vacuous under a high-privilege harness identity.