# Consumer contract
`authorize_workspace(context, groups, family)` decides current edit authority for one exact K1 Web family. If the family's 12 authority bytes equal the authenticated user's transaction ID, it authorizes only that unfiltered user authority and performs no Groups query. Otherwise it interprets the bytes as an exact concrete Group ID, rejects sentinel and filtered Groups, reads one current membership snapshot for the authenticated user and active model, and authorizes only when both are members of that Group.
User-byte identity wins over Group interpretation. The function performs no alias lookup, discovery, mutation, caching, retry, persistence, publication, or source disclosure. Dependency errors are returned unchanged.
The operation is unbenchmarked. User, sentinel, and filtered decisions are constant local work. An ordinary Group decision performs one synchronous Groups membership read and scans the returned user and model Group lists; dependency scheduling and storage latency have no finite bound owned by this library.