Mechanism
Access in the unified semantic discovery substrate is not a permission applied to results after they are found. It is a property of the traversal itself, evaluated at every anchor boundary by the same three-in-one traversal step that governs all other aspects of the traversal. A discovery object carries its access standing inside its own semantic state, specifically as a credential encoded in its policy reference field, and each anchor it reaches evaluates that credential against the anchor's access control configuration before admitting any transition into the anchor's neighborhood.
The credential is a governance token, not a payload of sensitive data. When a traversal is initialized, the originating entity's standing is resolved and encoded as a trust-scoped credential in the discovery object's policy reference field. In the biological-identity embodiment disclosed for this substrate, the credential is produced by the biological identity system: it attests to the user's identity continuity and trust level as computed by the biological trust slope validation, and it does so without containing the user's biological data. The discovery object carries the attestation, not the underlying signals that produced it.
At each anchor, the execution step of the three-in-one traversal step evaluates the discovery object's trust-scoped credential against the anchor's access threshold. Anchors governing restricted semantic neighborhoods, for example neighborhoods containing personal data, classified information, age-restricted content, or professionally restricted knowledge, require the credential to satisfy the anchor's access threshold before the traversal is admitted into the neighborhood. The same execution step that evaluates policy constraints, lineage continuity, entropy bounds, and temporal validity also evaluates access standing. Access is one of the admissibility criteria, evaluated before a transition is committed, not after.
Scoped Visibility, Not Post-Hoc Denial
Visibility is shaped before retrieval is even attempted, because the anchor's neighborhood publication is itself scoped to the requester. The neighborhood publication is the description of an anchor's reachable semantic territory that the search step evaluates to produce the candidate transition set. Different discovery objects with different policy profiles receive different neighborhood publications from the same anchor: a discovery object with broad access credentials receives a comprehensive publication, and a discovery object with restricted credentials receives a narrower publication that excludes the semantic neighborhoods its policy profile does not authorize it to access.
The consequence is that an unauthorized neighborhood is not surfaced as a candidate and then refused. It is simply absent from the candidate transition set the search step produces for that discovery object. The discovery object does not enumerate, inspect, or address individual objects in a neighborhood it cannot reach, because the publication it received does not describe that territory. Where a transition is proposed against an anchor the credential does not satisfy, the execution step rejects it regardless of its semantic relevance, before the transition is committed.
One Index, Governed at the Boundary
The same traversal infrastructure serves users with different access levels without separate indices, separate search engines, or separate governance frameworks. A user with a high-trust biological identity credential traverses the same adaptive index as a user with a lower-trust credential, but the reachable semantic neighborhoods differ based on the governance configuration of each anchor. The index is not partitioned into per-user copies. It is universally traversable, with access governed at each anchor boundary by the three-in-one traversal step rather than at the level of the index as a whole.
Because the biological identity system produces persistent identity through behavioral continuity rather than session tokens, access scoping carries across sessions. A user who initiates a traversal in one session and resumes it in another is recognized as the same user, and the resumed traversal inherits the access scoping of the original session. This cross-session continuity matters most in agent reasoning mode and answer synthesis mode, where a traversal may span an extended period and the originating identity must remain consistently resolved throughout.
Capability-Constrained Accessibility
Access standing is not limited to identity trust. An anchor may advertise a capability requirement as part of its governance configuration: the computational affordances a discovery object must possess or have access to in order to traverse the anchor's neighborhood. Certain neighborhoods require specialized inference engines, real-time processing, multimodal evaluation, or computational resources beyond a constrained traversal's budget. At each traversal step, the execution step evaluates the discovery object's capability profile, encoded in the context block or in a dedicated capability field, against the anchor's capability requirement. If the profile does not satisfy the requirement, the transition is rejected regardless of its semantic relevance, and the rejection is recorded in the lineage as a capability-constrained non-admission, distinct from rejections due to policy violations, lineage discontinuity, or entropy exceedance.
This permits the index to incorporate neighborhoods with heterogeneous computational requirements without degrading traversal for less capable discovery objects. A discovery object originating from a constrained device is routed around neighborhoods that exceed its capacity, while a discovery object on a high-capability substrate can reach the full extent of the index. The constraint operates at the anchor level, not the index level, and the same index serves both.
Capability standing can also be certified. The skill gating mechanism produces capability certification tokens that attest to an entity's demonstrated proficiency in specific domains. A certification token incorporated into the discovery object's capability profile enables access to neighborhoods that require domain-specific certification: a discovery object carrying a medical domain certification token can traverse anchors governing medical knowledge neighborhoods that are inaccessible to discovery objects lacking the certification. This produces capability-gated depth, so specialized semantic content is reachable by entities qualified to interpret it without restricting the general infrastructure for entities that do not require specialized access.
Rights-Grade Content Governance
The execution step also enforces rights-grade content governance at every anchor boundary, treating creator attribution requirements, content licensing constraints, and forbidden content exclusions as structural preconditions for admission rather than annotations applied to results after they are identified. The admissibility evaluation considers whether a proposed transition to a semantic object requires attribution to a named creator and whether the result will carry that attribution, whether the transition is consistent with the licensing terms under which the object was contributed to the index, and whether the transition would expose the discovery object to content excluded by its policy reference field or by the anchor's governance configuration. Where the discovery object's context block and intent field are not consistent with an object's licensed uses, the transition is rejected regardless of its semantic relevance.
In answer synthesis mode the attribution requirement extends to the generated answer: the generation step must include attribution for all source objects whose content contributes to the synthesized answer, and failure to include attribution renders the generation step inadmissible. Content cannot be reached by a traversal that violates its governance requirements, because the execution step at the anchor governing the content's container rejects the transition before it is committed.
Governed Access Leaves a Record
Every admissibility determination is recorded in the discovery object's lineage field regardless of outcome. An access-scoped rejection is recorded as such, a capability-constrained non-admission is recorded distinctly from a policy violation, and the transitions that were evaluated and rejected are preserved alongside the reasons for rejection. The traversal result therefore carries a complete admissibility audit trail rather than the opaque provenance of conventional retrieval.
Because the admissibility evaluation operates on typed fields, policy identifiers, capability requirements, lineage hashes, and temporal validity windows, rather than on unstructured content, it is deterministic. Given the same discovery object state, the same anchor configuration, and the same proposed transition, it produces the same outcome. Any party with access to the lineage field, the anchor's governance configuration at the time of traversal, and the proposed transition can independently verify that an access determination was correct.
Disclosure Scope
Credentialed reader access in the unified semantic discovery substrate, comprising the trust-scoped credential encoded in the discovery object's policy reference field, the resolution of that credential from biological identity without storing biological data, the per-requester scoping of anchor neighborhood publications so that unauthorized territory is absent from the candidate transition set rather than refused after the fact, the evaluation of access standing as an admissibility criterion in the execution step alongside policy, lineage continuity, entropy, and temporal validity, capability-constrained anchor accessibility including skill-gated certification tokens, rights-grade content governance at anchor boundaries, and the recording of every access determination in the lineage field, is disclosed in United States Patent Application 19/647,395 at Sections 10.4, 10.5, 10.15, 10.16, and 10.18. This article describes that disclosed mechanism. The scope extends to embodiments in which access standing is resolved by means other than biological identity, provided access remains a credential carried in the discovery object's semantic state and evaluated at each anchor boundary by the same governed traversal step.