# K1 groups domain
This library is the stateless public vocabulary for K1 groups. It owns identities, exact group-name validation, action and outcome values, and owned projection result values. It makes no authorization decision and owns no persistence, index, lock, recovery, migration, compatibility protocol, KTO parsing, I/O, callback, or generic abstraction.
## Public API
```rust
pub use kcode_k1_invites::UserId;
pub use kcode_k1_txn_ordering::TxId;
pub const ALL_USERS: GroupId;
pub const ALL_MODELS: GroupId;
pub const LOCAL_MODELS: GroupId;
pub const ALL_MODELS_MEMBER: ModelId;
pub enum SentinelGroup { AllUsers, AllModels, LocalModels }
pub struct GroupId { /* private fields */ }
pub struct ModelId { /* private fields */ }
pub struct GroupName { /* private fields */ }
pub enum GroupRole { User, Admin, Owner }
```
`SentinelGroup`, `GroupId`, `ModelId`, and `GroupRole` implement `Copy`, `Clone`, `Debug`, `Eq`, `Hash`, `Ord`, `PartialEq`, and `PartialOrd`; `GroupName` omits only `Copy`. All struct fields are private. `GroupId` exposes `new`, `txid`, and `sentinel`; `ModelId` exposes `from_bytes`, `as_bytes`, and `into_bytes`; `GroupName` exposes `new`, `as_str`, and `into_string`.
`GroupName::new` accepts exact UTF-8 values of 1 through 128 bytes with no `char::is_control` character and at least one non-whitespace character. Its exact errors, in validation order, are `"group name must be 1 through 128 UTF-8 bytes"`, `"group name must not contain control characters"`, and `"group name must contain a non-whitespace character"`; accepted text is not altered and names are not unique.
`ALL_USERS`, `ALL_MODELS`, and `LOCAL_MODELS` are synthetic immutable `GroupId` sentinels wrapping TxId bytes ending in `1`, `2`, and `3`, respectively, after `[255, 75, 49, 71, 82, 80, 0, 0, 0, 0, 0]`. `GroupId::sentinel` recognizes exactly them.
`ALL_MODELS_MEMBER` is a `ModelId` with exact bytes `*b"ALL_MODELS......................"` (10 ASCII name bytes and 22 dots). It is an ordinary stored model-membership marker, distinct in type and representation from the synthetic `GroupId` sentinel `ALL_MODELS`. This package does not expand it to actual models; a later index package may do so.
`Group`, `GroupMemberships`, actions, outcomes, and `projection_values` retain their documented public accessors, variants, constructors, ownership, and deterministic local behavior. Calls perform no I/O, locking, waiting, retry, timeout, callback, or background work.