u4 · trust boundary
Authority stays separate from rendered content
agent + CLIaccount bearer
control APIaccount-scoped state
browser Playerscreen/runtime grants
isolated releaseplacement capability only
ScreenRig is not public file hosting. Protected releases, media, and K/V require current screen-manifest authority. Knowing an ID, path, upload, or object key never authorizes a read; there is no arbitrary listing or public-download API.
Account bearer tokens stay with the CLI and account API. Uploaded applications run on isolated release origins. Public screen URLs are unlisted read-only playback, not confidentiality; anyone allowed to view a screen can inspect bytes delivered to that browser.