--- id: MEM-9 family: GR-MEM level: core profiles: [storage-api, runtime] posture: normative-target added: "1.0" changed: "1.0" source: https://flowdrop.io/spec/rules/gr-mem/mem-9 specification: FlowDrop Workflow Specification 1.0-draft licence: CC BY 4.0 --- # MEM-9 — Driving a session is a write, and an absent identity owns nothing *GR-MEM (Part I) · level: core · profiles: storage-api, runtime · added in 1.0* A turn spends the owner's memory, so the right to watch a conversation is not the right to continue it. And the caller with no identity is not a caller whose identity happens to be zero. ## The rule > **Normative.** This is the rule. > > 1. Authorization to read a session does not authorize driving it. > > 2. A principal that may only view a session must not be able to send it a turn, stop it or reset it, because the turn runs under the session owner's identity and reads and writes the owner's memory (MEM-8). > > 3. Every ownership test requires a real identity on both sides. > > 4. A principal carrying no identity never owns anything, and a session carrying no owner is owned by nobody rather than by everybody, so an unidentified caller never acquires ownership of a session, a transcript or a run snapshot by matching one absent identity against another. ## Related rules - Names: MEM-6, MEM-8, MEM-15 - Referenced by: MEM-15 --- Rule identifiers are permanent and are never renumbered. This specification carries no implementation status: each implementation publishes its own standing against these rules. Licensed CC BY 4.0.