Sensitive material handling
Secret material is owned by ahri_tre_secrets. Application configuration may
contain canonical logical references and declared Injected versions; Client
bootstrap contains no Secrets.
Injected material is snapshotted at startup where required. Managed material is resolved through narrow capabilities, authenticated envelopes, and exact version provenance. A newly authorized operation may resolve its selected Managed reference again; workflow code does not reopen the store.
Public output, logs, diagnostics, protocol envelopes, Session metadata, provenance summaries, and package artifacts must never contain passwords, tokens, authorization codes, private keys, signed credential values, inline connection credentials, credential-bearing paths, or live handles.
Replacement and removal are owner-aware transactions. Active Session and Datastore references are durable evidence. If authoritative inspection is unavailable or commit state is uncertain, the operation fails closed and keeps the recoverable material.
Tests use explicit canary literals inside test modules and assert they are absent from every public representation. Test helpers do not create public credential-field DTOs in production crates.