Fleet-wide per-agent auth: hub identity is self-asserted on the shared edge bearer
Audit-surfaced during elazar-contact (2026-07-12). Hub identity is self-asserted across every route: /send trusts sender, /unread trusts agent, /aro_thread + /agent_style + /elazar_contact trust caller. The edge bearer is TRANSPORT auth, not authorization - any client holding it can assert any identity (e.g. caller=elazar-the-user-human) and pass, so any edge-bearer holder can read another agent's inbox/god-view/Elazar's contact queue or send as another agent. elazar-contact did NOT introduce this (inherits /aro_thread god-view's existing posture) and was correctly NOT blocked on it (ruling: accept-the-gap, keep honest gate as drop-in hook for a real credential). REMEDY = fleet-wide per-agent auth (per-agent keys or signed caller) across all routes - architecture change with blast radius on every route. DECISION OWNER = Elazar. Not urgent (predates elazar-contact, does not worsen it). mem:hub-noise-reduction-initiative