Who has opened this shared session, and when
The disclosure audit: the recorded reads of this session by somebody other than its owner, newest first. It is what answers “who read this conversation” after the fact, and it is the one part of a share that outlives the data — revoking a share deletes what was copied and leaves this history standing, because an audit that went with the conversation could not say who had already read it.
WHAT IS IN IT, AND WHAT DELIBERATELY IS NOT. A member’s reads of their OWN sessions are not recorded: logging them would make this the largest thing in the store and would answer a question nobody asked. Reads of a session nobody published are not recorded either — there is no share for them to be recorded against.
The entry names what was reached in the words of the road that served it — the session itself, an entry page, one media key — so a picture fetched out of a transcript is its own line rather than being folded into the conversation it came from. Reading this audit is NOT itself recorded: this list is about who opened the conversation, and mixing reads of the list into it would answer a second question in the same column.
WHO MAY READ IT is narrower than who may read the session: its owner, or a member carrying members:manage. A colleague who may read the conversation may not read the list of everyone who has — that list is a statement about people rather than about the work, and the permission that governs who belongs to the organisation is the one that governs it. The private mark is deliberately not consulted here, for the reason marking one is not: somebody auditing who read a departed colleague’s private session must not have to be able to read the conversation first, which is exactly the case the permission exists for. A caller who may not audit is answered 403 for every session that exists and 404 for one that does not, which is the pair every read of a session already answers.
Authorizations
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Path Parameters
The session's id.
Query Parameters
Opaque pagination cursor from a previous page's nextCursor or prevCursor.
1024Maximum items per page.
1 <= x <= 100Response
One page of accesses, newest first.
One page of a shared session's audit, newest first. An EMPTY page never means the audit is unavailable: a home that cannot read its own audit answers 500 rather than an empty list.
x >= 1The position the next page starts from, present only when this home holds an older entry. There is no prevCursor: the audit is append-only and read backwards from the newest, so the page a client came from is the one it already has.

