--- id: SNAP-2 family: RT-SNAP level: core profiles: [runtime, editor-client] posture: normative-target added: "1.0" changed: "1.0" source: https://flowdrop.io/spec/rules/rt-snap/snap-2 specification: FlowDrop Workflow Specification 1.0-draft licence: CC BY 4.0 --- # SNAP-2 — Snapshot access is decided on the snapshot, and absence answered first *RT-SNAP (Part II) · level: core · profiles: runtime, editor-client · added in 1.0* ## The rule > **Normative.** This is the rule. > > 1. Reading or deleting a snapshot loads it by execution id and asks it for view or delete authority: a snapshot that does not exist is `404`, one the caller may not reach is `403`, and absence is answered before denial. > > 2. A read that finds the record but no readable payload answers `404` as well, never a partial document. > > 3. The list door does not ask per record: it narrows the query by ownership, so a snapshot belonging to another principal is absent from the list rather than a denial on it. ## Related rules - Names: SNAP-1, PIPE-6 - Referenced by: PIPE-6, SNAP-1 --- Rule identifiers are permanent and are never renumbered. This specification carries no implementation status: each implementation publishes its own standing against these rules. Licensed CC BY 4.0.