- Shipped
- October 11, 2026 at 9:50 AM UTC
- Author
- Kamo
- Commit
- 884f3b6
RecordingController now runs tenancy (404), then the PHI capability (403), then CallRecordingAccess through access/RecordingAccessService (403 RECORDING_NOT_PERMITTED with a denied audit row). A ?st= stream token reads its rights from member_rights_applied and is never god; the lead path needs the CRM app (CrmAppGate, 30 s cache). PhiPlaybackAuthorizer keeps only the capability half, which voicemail playback also calls. Permitted reads write BASIS=<basis> into the audit justification. voipservice declares the org graph and evicts it on ****************
