The current user unit wins the boot race but still runs as the human whose Personal key the lock is meant to evict. Record the target souveraine-session principal, its narrow Wayland/PAM/data reach, and the fact that the rich shell is presentation—not release authority.
Join the older storage and authority audits to the SAF principal contract. Passwd entries are not isolation while one human-owned process still executes every agent, and the existing souveraine account is machined's—not Souvie's.\n\nKeep the readiness task honest: its current health fields inventory paths, but do not yet prove admission or the UID handling a live turn.
souveraine-secrets is live on the phone (reboot-verified, keyring
masked) — TASK-11 complete, moved to tasks/archive/ with the outcome.
STORAGE-ENCRYPTION.md: add the doc (design of record, 2026-07-20) with
status updated to match code — secrets-store AEAD + machine wrap built,
Argon2id wrap built with ingress pending; the derive_storage_key gap
paragraph now scoped to what remains. Add session handoff.