> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Who has opened this shared session, and when

> The disclosure audit: the recorded reads of this session by somebody other than its owner, newest first. It is what answers "who read this conversation" after the fact, and it is the one part of a share that outlives the data — revoking a share deletes what was copied and leaves this history standing, because an audit that went with the conversation could not say who had already read it.
WHAT IS IN IT, AND WHAT DELIBERATELY IS NOT. A member's reads of their OWN sessions are not recorded: logging them would make this the largest thing in the store and would answer a question nobody asked. Reads of a session nobody published are not recorded either — there is no share for them to be recorded against.
The entry names what was reached in the words of the road that served it — the session itself, an entry page, one media key — so a picture fetched out of a transcript is its own line rather than being folded into the conversation it came from. Reading this audit is NOT itself recorded: this list is about who opened the conversation, and mixing reads of the list into it would answer a second question in the same column.
WHO MAY READ IT is narrower than who may read the session: its owner, or a member carrying `members:manage`. A colleague who may read the conversation may not read the list of everyone who has — that list is a statement about people rather than about the work, and the permission that governs who belongs to the organisation is the one that governs it. The private mark is deliberately not consulted here, for the reason marking one is not: somebody auditing who read a departed colleague's private session must not have to be able to read the conversation first, which is exactly the case the permission exists for. A caller who may not audit is answered 403 for every session that exists and 404 for one that does not, which is the pair every read of a session already answers.



## OpenAPI

````yaml /en/openapi/v3-current/narya.yaml get /v1/sessions/{sessionId}/share/disclosures
openapi: 3.1.0
info:
  title: Narya Host API
  version: 1.0.0
  description: >-
    The contract between the Narya host and every client. One long-lived host
    serves this API over a Unix socket in your Narya home. The terminal client
    and the one-shot command that Lerian ships drive this API, and a client you
    write drives the same one.


    Requests authenticate with a bearer token issued by the identity provider
    the host is configured with. An operation that declares another security
    scheme also accepts that credential. A request without a valid credential
    gets 401 with NRY-0011. A caller whose role lacks the permission an
    operation needs gets 403 with NRY-0028.


    Submitting a message returns 202 with a turn id. Everything the turn
    produces streams over GET /v1/events as server-sent events with a typed
    envelope, and a stream resumes from a Last-Event-ID header.


    One error envelope: code, title and message. Codes are NRY- followed by four
    digits. Cursors are opaque.
servers: []
security:
  - bearerAuth: []
tags:
  - name: host
    description: The host process itself — version, uptime, mode, store.
  - name: sessions
    description: Durable conversation containers. Archive, never destroy.
  - name: messages
    description: Submitting work into a session and interrupting it.
  - name: events
    description: The server-sent event stream every client consumes.
  - name: lanes
    description: Parallel tracks inside a session — main, subagent, side.
  - name: agents
    description: Named recipes — instructions, tools, model, policy. Read-only in v1.
  - name: ladder
    description: >-
      What a person can type: the skills and command files in force for one
      repository, and expanding one into text. Five origins merged, nearest
      winning a name, the repository's own rungs gated on trust.
  - name: permissions
    description: Pending permission asks, decisions, and the decision audit.
  - name: intercom
    description: Sessions on one machine finding and messaging each other.
  - name: packages
    description: The one thing a user installs — resources, Go code, or both.
  - name: extensions
    description: >-
      Host-side extensions and the operations each exposes over the wire. This
      is the generic lane a host extension uses to serve its own client half (a
      TUI component, a web panel) or any API-only consumer, without adding
      routes to this contract.
  - name: workflows
    description: Deterministic multi-agent orchestration runs.
  - name: providers
    description: Model suppliers, their auth state, and the model catalogue.
  - name: monitors
    description: >-
      Long-running watchers a session keeps beside its conversation — a test
      runner in watch mode, a build, a log being followed. Started by the model
      or by the person, always listed, always killable.
  - name: records
    description: The queryable local record of everything that happened.
  - name: environments
    description: >-
      Where a session's code lives and its commands run — this machine, or a
      container narya operates. A session that names none runs here.
  - name: schedules
    description: >-
      Work the host's own clock starts with nobody present — a repository, a
      prompt, a rule and what one fire may spend. Cancel, never destroy.
  - name: sharing
    description: >-
      Publishing a session from a developer's own home to the organisation's,
      and what is held back before a byte leaves the machine.
  - name: refinements
    description: >-
      What this owner has taught narya and allowed it to keep — distilled facts,
      and the skills, agents and commands the model wrote for itself. Propose,
      read, consent, roll back. Nothing here fires until a person answers.
  - name: platform
    description: >-
      Calls Lerian's control plane made to a home it hosts, as this home
      recorded them.
paths:
  /v1/sessions/{sessionId}/share/disclosures:
    parameters:
      - $ref: '#/components/parameters/SessionIdParam'
    get:
      tags:
        - sharing
      summary: Who has opened this shared session, and when
      description: >-
        The disclosure audit: the recorded reads of this session by somebody
        other than its owner, newest first. It is what answers "who read this
        conversation" after the fact, and it is the one part of a share that
        outlives the data — revoking a share deletes what was copied and leaves
        this history standing, because an audit that went with the conversation
        could not say who had already read it.

        WHAT IS IN IT, AND WHAT DELIBERATELY IS NOT. A member's reads of their
        OWN sessions are not recorded: logging them would make this the largest
        thing in the store and would answer a question nobody asked. Reads of a
        session nobody published are not recorded either — there is no share for
        them to be recorded against.

        The entry names what was reached in the words of the road that served it
        — the session itself, an entry page, one media key — so a picture
        fetched out of a transcript is its own line rather than being folded
        into the conversation it came from. Reading this audit is NOT itself
        recorded: this list is about who opened the conversation, and mixing
        reads of the list into it would answer a second question in the same
        column.

        WHO MAY READ IT is narrower than who may read the session: its owner, or
        a member carrying `members:manage`. A colleague who may read the
        conversation may not read the list of everyone who has — that list is a
        statement about people rather than about the work, and the permission
        that governs who belongs to the organisation is the one that governs it.
        The private mark is deliberately not consulted here, for the reason
        marking one is not: somebody auditing who read a departed colleague's
        private session must not have to be able to read the conversation first,
        which is exactly the case the permission exists for. A caller who may
        not audit is answered 403 for every session that exists and 404 for one
        that does not, which is the pair every read of a session already
        answers.
      operationId: listSessionDisclosures
      parameters:
        - $ref: '#/components/parameters/CursorParam'
        - $ref: '#/components/parameters/LimitParam'
      responses:
        '200':
          description: One page of accesses, newest first.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DisclosurePage'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    SessionIdParam:
      name: sessionId
      in: path
      required: true
      description: The session's id.
      schema:
        type: string
        format: uuid
    CursorParam:
      name: cursor
      in: query
      required: false
      description: >-
        Opaque pagination cursor from a previous page's nextCursor or
        prevCursor.
      schema:
        type: string
        maxLength: 1024
    LimitParam:
      name: limit
      in: query
      required: false
      description: Maximum items per page.
      schema:
        type: integer
        minimum: 1
        maximum: 100
        default: 25
  schemas:
    DisclosurePage:
      type: object
      description: >-
        One page of a shared session's audit, newest first.

        An EMPTY page never means the audit is unavailable: a home that cannot
        read its own audit answers 500 rather than an empty list.
      required:
        - items
        - limit
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/Disclosure'
        limit:
          type: integer
          minimum: 1
        nextCursor:
          type: string
          description: >-
            The position the next page starts from, present only when this home
            holds an older entry. There is no prevCursor: the audit is
            append-only and read backwards from the newest, so the page a client
            came from is the one it already has.
      examples:
        - items:
            - actor: user_01HZX3Q8N4KDPYV2A7C9M5T6RB
              reached: entries
              at: '2026-09-08T11:04:21.000Z'
            - actor: user_01HZX3Q8N4KDPYV2A7C9M5T6RB
              reached: media/screenshot.png
              at: '2026-09-08T11:04:19.000Z'
          limit: 25
    Disclosure:
      type: object
      description: |-
        One access to a shared session: who reached what, and when.
        It names no share id and no session id.
      required:
        - actor
        - reached
        - at
      properties:
        actor:
          type: string
          description: >-
            The issuer's subject for whoever read it. It is an identifier and
            not a display name: names are the identity provider's to answer,
            they change, and a row in a table that never changes would go stale
            carrying one. A client that wants a face resolves it, exactly as it
            does for a session's owner.
        reached:
          type: string
          description: >-
            What was served, in the words of the road that served it: the
            session itself, an entry page, one media key. Deliberately not a
            fixed vocabulary — the honest answer is which surface was asked for,
            and an enum would have to be extended by every operation added
            afterwards, with an audit recording the wrong surface in the
            meantime.
        at:
          type: string
          format: date-time
          description: When the read was served, on the clock of the home that served it.
    Error:
      type: object
      description: >-
        The single error envelope every operation returns. Codes are NRY-
        followed by four digits and are catalogued in the top-level
        x-error-catalog extension.
      required:
        - code
        - title
        - message
      properties:
        code:
          type: string
          pattern: ^NRY-[0-9]{4}$
          description: Machine-readable error code from the NRY catalogue.
        title:
          type: string
          maxLength: 256
          description: Short human-readable summary of the error class.
        message:
          type: string
          maxLength: 4096
          description: Specific, actionable description of what went wrong.
        fields:
          type: object
          description: Per-field validation problems.
          additionalProperties:
            type: string
      examples:
        - code: NRY-0002
          title: Session not found
          message: >-
            No session with id 6b9f6d2e-1c3a-4f5b-9d7e-2a8c4e6f0b1d exists on
            this host.
  responses:
    BadRequest:
      description: Malformed request — invalid parameter, cursor, or JSON body.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Forbidden:
      description: >-
        The caller is authenticated and is not allowed this operation (NRY-0028
        or NRY-0030).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: The addressed resource does not exist on this host.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    InternalServerError:
      description: The host failed — including a store that refuses writes (NRY-0012).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Enforced on every transport, with no exempt operation. A person's
        request — over the default local unix socket exactly as over a TCP
        listener — must carry a JWT issued by the configured identity provider,
        which the host verifies itself against that issuer's key set: signature,
        issuer, expiry, and the person and organisation it names. Requests
        without a valid one receive 401 NRY-0011. The socket's file permissions
        are transport and are not an authorisation.

````