# kcode-k1-access-kmap 0.1.0
## API and purpose
`K1AccessKmap` is a stateless in-process facade over already-open `K1Access`,
`K1AccessProfiles`, and `K1Kmap` handles. `open` validates the fixed `k1-kmap`
subsystem and retains only those three `Arc`s. The methods are `create_node`,
`get_node`, `open_node`, `update_node`, and `apply_measurements`. Every method
receives separate `UserId` and `ModelId` values; creation also receives an
`AccessProfile`. Kmap transaction and option types are reexported.
## Identity and authority
Public node and connection identities are `AccessId`s. Each Access target has
subsystem `k1-kmap` and object bytes equal to the raw twelve-byte Kmap `NodeId`;
raw IDs never cross this API. Missing access, insufficient authority, a wrong
subsystem, and non-twelve-byte target data all return `node unavailable`.
Reads require view. Updates atomically validate source view+manage and target
view in one batch. Measurements deduplicate identities, aggregate roles, and
require source view+manage and target view before submitting one ordered batch.
Mixed authority therefore causes no partial raw write.
Creation first resolves the profile for `RequestPrincipal(user, model)`, then
batch-validates initial targets, creates the raw node, and creates its Access
wrapper with immutable resolved authorizations. If that final step fails, the
error marks the boundary and a possible inaccessible raw orphan remains. There
is no retry or rollback.
## Filtering
`get_node` reverse-resolves outgoing targets in one batch, omits hidden edges,
and preserves visible relative order. `open_node` validates the root and uses a
per-batch candidate callback that reverse-resolves the whole candidate batch.
Denied candidates do not enter Kmap's frontier, reads, scoring, budget, or RNG.
Allowed mappings live only for that invocation. A loaded node lacking a mapping
is a dependency-consistency error without raw identity disclosure.
## Concurrency, performance, and errors
The facade has no lock, cache, thread, retry, background task, or mutable state;
concurrency is delegated to the retained handles. Authorization is batched for
connections and deduplicated measurement roles. There are no facade count
limits, and empty inputs remain complete valid operations. Dependency failures
receive short operation context while retaining the complete child message.
Safe node rejection never exposes a hidden target, position, count, weight,
order, or raw ID.
The package provides no discovery/listing, HTTP, Ktool registration, crawler,
daemon, UI, migration, automatic retrieval feedback, cross-subsystem
transaction, timeout framework, rollback framework, or publishing workflow.