# Scopes & tenancy

Understand permissions and the owner scope attached to each request.

## Scopes

Reads use context:read. Save, remove and data-request commands use content:write. The server rejects missing scopes before the domain operation runs.

## Tenancy selector

Use x-genviral-tenancy: personal or an authorized workspace UUID. This selects the owner context; it does not create membership or turn public catalogue evidence into private customer data.

## Saved items

Bookmarks belong to the canonical authenticated user and are shared with Genviral. They are private account data and are never copied into the global competitor catalogue.
