--- id: MEM-15 family: GR-MEM level: core profiles: [storage-api] posture: normative-target added: "1.0" changed: "1.0" source: https://flowdrop.io/spec/rules/gr-mem/mem-15 specification: FlowDrop Workflow Specification 1.0-draft licence: CC BY 4.0 --- # MEM-15 — A denial is final, and a message is not editable *GR-MEM (Part I) · level: core · profiles: storage-api · added in 1.0* ## The rule > **Normative.** This is the rule. > > 1. A denial by these access rules is final. > > 2. Where an implementation offers extension points that contribute to an access decision, none of them may grant what these rules have denied. > > 3. A session message is never updatable or deletable except at the administrative tier. > > 4. A message whose parent session cannot be loaded is denied rather than left undecided, since the ownership it would be judged against cannot be established. ## Related rules - Names: MEM-9 - Referenced by: MEM-9 --- Rule identifiers are permanent and are never renumbered. This specification carries no implementation status: each implementation publishes its own standing against these rules. Licensed CC BY 4.0.