- Shipped
- August 15, 2026 at 1:48 AM UTC
- Author
- Kamo
- Commit
- 1f3bde4
Seeing every organization and being able to enter one are the same decision — the list exists so an operator can find the organization they are about to support — so /all-networks now asks for SYSTEM_USER instead of ownership of the top-level org. A platform administrator granted System User access could previously enter any organization while being unable to see the list of them. resolveFromSession supplies the rest of the rule and replaces the hand-rolled version this handler carried: the caller must be in the top-level organization, the System User's own sessions are refused, and an owner or an open god-mode window still qualifies without an explicit grant.