repo access list now folds owner, org admin, direct grant, team grant and org membership into one row per account with the highest role and its source ({user, role, source}), where before it listed direct grants only. ListAccess had no other caller and goes.
Outsiders get one rule for an org: existence and members are public, teams are for members, and a non-member asking for teams is refused (exit 4) rather than told the org does not exist. Users page says so. Store unit test and an e2e covering both.
Closes #200
retargeted from tag-protection to main: !340 merged
2026-09-08 02:35 UTC