# Access state
This library owns the in-memory K1 access projection, immutable profile links, and unique target index.
## Public API
- `AccessState::new(Vec<StoredAccess>)` rebuilds a complete projection.
- `create(StoredAccess)` inserts one complete committed record.
- `replace(AccessId, TxId, AccessPolicy)` replaces revision and policy fields.
- `profile_id(AccessId) -> Option<ProfileId>` exposes a known record's immutable profile link.
- `authority(AccessId) -> Option<Authority>` exposes a known record's immutable authority metadata; callers must authorize before disclosure or use.
- `controller_profile_ids(&AccessContext, &[AccessId], &[GroupId]) -> Vec<Option<ProfileId>>` batch-reads profile links controlled by the current user.
- `check` and `check_many` evaluate access with subsystem and group-revision evidence.
- `resolve_visible_targets` resolves exact targets visible in the expected subsystem.
- `accepts_edit_witness` matches an exact authority or normalized editor without membership evaluation.
Construction and creation bind the access ID, committed revision, and non-null immutable profile ID from one `StoredAccess`. They reject duplicate access IDs or targets. Rebuilding preserves every profile link. Replacement requires an existing access ID and the same authority, preserves its target and profile ID, and replaces its revision, editors, and viewers.
`authority` is trusted immutable metadata lookup only. It performs no authorization, filtering, concealment, mutation, or I/O; callers must authorize before disclosure or use.
`controller_profile_ids` discloses a profile link only when the immutable authority is not filtered and is either the context user or a group in the supplied current user-group slice. Editors, viewers, model-group membership, and unknown IDs do not disclose links. Results preserve input positions and duplicates.
Unknown, wrong-subsystem, filtered, and inaccessible checks reveal no target or revision evidence. An allowed check includes both supplied snapshot revisions and reveals the target only when viewing is allowed. Batch results preserve input order and duplicates; reverse resolution returns an ID only for an exact, visible target in the expected subsystem.
Operations are not yet benchmarked. Construction scales with records and distinct policy bodies; indexed mutations and profile and authority lookup perform expected constant-time lookup plus value hashing, checks scan delegated policy and membership inputs, and batches scale with input positions. Operations perform no I/O.