← Event kinds
- wire scope
- durable_event
- reducer input
- yes
- payload
- Circle materialized membership state. Uses the same membership_state enum as ak.member.state (join/knock/leave/ban), scoped to a Circle. Invite remains a separate pending workflow. A join carries the producer-signed parent_membership_revision; admission MUST verify in the accepting cut that the complete member_id's parent Realm member_state current is `join` at exactly that revision, otherwise failed_precondition reason=circle_member_must_be_realm_member. Effective Circle membership additionally requires the parent current to still carry that revision; parent leave, ban or rejoin never synthesizes this Event and never revives an old Circle join. See zh/models/circle.md §9.1. Every illegal membership FSM edge, including an unregistered same-state transition, is rejected with failed_precondition reason_code=invalid_membership_transition and zero writes. An authorized Circle administrator may perform leave->join with ak.circle.member.add.others and the required same-unit audit, without a Circle invitation workflow; parent join revision, Circle active status, ban and MLS gates remain mandatory.
Wire scope
durable_event ·
Persisted canonical history & reducer input.
Source