# Access state
This library owns the in-memory K1 access projection and its unique target index.
## Public API
```rust
use kcode_k1_access_store::StoredAccess;
use kcode_k1_access_types::{
AccessCheck, AccessContext, AccessId, AccessPolicy, Authority, GroupId, SubsystemId, Target,
TxId,
};
pub struct AccessState { ... }
impl AccessState {
pub fn new(records: Vec<StoredAccess>) -> Result<Self, String>;
pub fn create(&mut self, record: StoredAccess) -> Result<(), String>;
pub fn replace(
&mut self,
access_id: AccessId,
revision: TxId,
policy: AccessPolicy,
) -> Result<(), String>;
pub fn check(
&self,
context: &AccessContext,
access_id: AccessId,
expected_subsystem: SubsystemId,
user_groups: &[GroupId],
model_groups: &[GroupId],
groups_revision: Option<TxId>,
) -> AccessCheck;
pub fn check_many(
&self,
context: &AccessContext,
access_ids: &[AccessId],
expected_subsystem: SubsystemId,
user_groups: &[GroupId],
model_groups: &[GroupId],
groups_revision: Option<TxId>,
) -> Vec<AccessCheck>;
pub fn resolve_visible_targets(
&self,
context: &AccessContext,
targets: &[Target],
expected_subsystem: SubsystemId,
user_groups: &[GroupId],
model_groups: &[GroupId],
) -> Vec<Option<AccessId>>;
pub fn accepts_edit_witness(&self, access_id: AccessId, witness: Authority) -> bool;
}
```
Construction and creation reject duplicate access IDs or targets. Replacement requires an existing access ID and the same authority, preserves its target, and replaces its revision, editors, and viewers.
Unknown, wrong-subsystem, filtered, and inaccessible checks reveal no target or revision evidence. An allowed check includes both supplied snapshot revisions, and reveals the target only when viewing is allowed. Batch results preserve input order and duplicates; reverse resolution returns an ID only for an exact, visible target in the expected subsystem. `accepts_edit_witness` matches only the exact authority or a normalized editor and performs no membership evaluation.
Operations are not yet benchmarked. Construction scales with records and distinct policy bodies; indexed mutations perform expected constant-time lookup plus value hashing, checks scan delegated policy and membership inputs, and batches scale with input positions. Operations perform no I/O.