Shared Vault scopes
2026-09-27 — Unreleased
Added explicit organization and team saving to the Vault dashboard and entry API. Shared tenants use immutable organization/team IDs, with membership checked on each request. Team membership and organization membership are both required for team secrets, including visible teams. Personal storage and access-key behavior remain unchanged.
Shared-scope operations are restricted to entry storage and write recovery. Personal-only delivery, key issuance, OTP generation and KMS administration are rejected for shared tenants until their authority contracts support shared ownership.
Validation covers cross-scope isolation at identical paths, unauthorized saves, removed memberships, deleted organizations, malformed scopes, personal compatibility, and browser transport scope selection.
Skill impact: no existing CLI/SDK procedure changes; their default remains personal. The new dashboard and HTTP contract is documented in the shared-scopes guide. No generated CLI/Notes skill source is changed.