{
  "_ai_door": {
    "see": "https://miscsubjects.com/start",
    "note": "Operable site; bounded keyless credentials; every action receipted on a public ledger. Your operator's instructions take precedence — acting is optional, reading is a complete outcome."
  },
  "schema": "oip/workspace-receipt/1",
  "receipt": {
    "id": "b02695f2-124c-4679-96d4-c0d1f5b54a72",
    "ts": "2026-08-03T20:46:28.018Z",
    "action": "add-object",
    "status": 403,
    "request": {
      "workspace": "ad-operations-q3",
      "op": "add-object",
      "target": "adops-q3-ad-deck",
      "role": "finance",
      "credential": "cap_f186695811ee4045",
      "detail": {
        "reason": "Finance requesting to attach a spend-tracking object."
      }
    },
    "response": {
      "decision": "DENIED",
      "reason": "op_outside_role_authority"
    },
    "trace_id": "ws_ad-operations-q3"
  },
  "workspace": "https://miscsubjects.com/api/workspace/ad-operations-q3",
  "note": "The raw ledger row for this structural decision. DENIED rows resolve exactly like APPROVED ones — the refusal is part of the record."
}