The field shipped in loomctl, so this document was describing a three-column
format that no longer exists.
Access is checked once at fetch and the copy is durable, so an adoption's
legitimacy rested on the relative visibility of two repositories — a fact
recorded nowhere and changeable by a checkbox a year later by somebody who never
saw the adoption.
The design is loom-cli's. Record public or not-public and never private, because
an anonymous request cannot tell two repositories private to different people
apart, and that is exactly the case where private into private widens access.
One request per run rather than per document, since only your own visibility must
be current. Re-check a source only when the alarm would fire, since a stored
visibility decays in both directions.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>