Pond Admins can answer "what can X actually see/do here?" — load-bearing for
trust in the grant system (permissions.md §UI obligations).
- shared: `explainPageCapability` — the resolver's decision chain (deciding
level + the single deciding grant), sharing one code path with the boolean
`resolvePageCapability` (now a thin wrapper), so the trace can never diverge
from real access. Unit-tested against the permissions.md worked examples.
- api: `GET /ponds/:id/effective-permissions?subjectType=&subjectId=&pageId=`
(Pond-Admin-gated, one pond only) resolves as the chosen subject (a user with
their real Site-Admin flag, all signed-in users, or the public), optionally
against a page, and returns the read + write outcome with the deciding rule
enriched with subject/scope names.
- web: `EffectivePermissionsInspector` in Pond Settings — pick a subject and
optionally a page → see the resolved read/edit verdict, the level that
decided it, and the deciding rule spelled out as a de/en sentence (reusing
the #55 sentence renderer). Hidden from non-admins.
- tests: explain-mode unit tests (worked examples + trace-matches-boolean);
`inspector.e2e.db.test.ts` (deciding rule on a labelled page, pond-level base
capability, public default-closed, Pond-Admin gating); a browser assertion in
the access-rules pack.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1