…
- **member**: reads the project, writes topics and objects, uploads files, makes AI tokens for themselves.
- **mod**: also edits the landing page and special pages, and replaces or deletes anyone's files.
-- **admin**: also sees **This project** on the **Settings** page (in the user menu, in the admin colour): **Members** (who's in, their roles, requests, invites), **Project** (versions, level, who can join), **Quotas** (what the plan allows and what's used) and **Init**. The owner is an admin.
-- **god** is d2's own administrator: admin in every project.
+- **admin**: also sees **This project** on the **Settings** page (in the user menu, in the admin colour): **Members** (who's in, their roles, requests, invites), **Project** (versions, level, who can join, who can read and change it), **Quotas** (what the plan allows and what's used) and **Init**. The owner is an admin.
+- **the Architect** is d2's own administrator: admin in every project.
-What each topic and object may be seen or changed by is set by its class (`@view`, `@edit`); settings, for example, are for mods. The landing page is always public, since it's where people log in.
+### What may be read, and by whom
+Everything readable carries two levels, **view** (who may read it) and **edit** (who may change it), each one of `public`, `member`, `mod` or `admin`. One question is asked of the same four places, the most specific first:
+
+1. the topic's own frontmatter (`view: public`, `edit: mod`): a mod's to add or change;
+2. its category, or an object's class (`@view`, `@edit`): `Settings:` topics are the mods', `Spec:` topics are changed by mods, your `Memory:` and `Skill:` topics are yours (`edit: owner` means you, plus the mods), and the logs are only ever added to;
+3. the project's own **view** and **edit**, on **Admin → Project**: an admin's to change, and what makes a project private;
+4. and if nothing says otherwise, `member` and `member`.
+
+A page you may not read says so at its own address, with **Log in** if you aren't logged in, and names the level it wants if you are; it never appears in a list, a search, the tags or the history either, and a link to it reads as plain text. The landing page is always public, since it's where people log in. An AI token can only ever be narrowed further, by `ai-access` on a topic and by the level the token was made with.
+
## Let people in
…
- **request** (the default): people press *Request to join* on the landing page; you approve or deny on **Admin → Members**, and they're told.
- **open**: anyone who's logged in can press *Join* and becomes a member.
-- **private**: members only. Visitors see at most the landing page, and only people you add get in.
+- **invite**: only people you add get in. To keep visitors out of the project as well, set **view** to `member` on **Admin → Project** (that, not the join setting, is what makes a project private).
**Invite someone** by email on **Admin → Members**, with the role they'll have. The invite is a link, good for 7 days, and works whatever the join setting; opening it (logged in as that email) makes them a member. A new invite to the same person replaces the old one.
…