Participation is the gate. Navigator resolves the code to a Project, authorizes the caller through that Project's
participation ledger, and answers a scope miss with 404 rather than 403 — a 403 would confirm to somebody not on the
matter that a Project with this code exists. A code naming no Project gets the identical response, so the status
discloses nothing about which refusal it was.
What changed is that there is nothing to add: a Project either has a portal repository or it does not. What did not
change is that you cannot guess your way into a route.
Two paths, and it is worth being precise about which is which. Standing up an installation and building on it is
self-serve: navigator ops gcp setup puts the stack on your own Google Cloud project, and from there your /api,
your /mcp, and whatever you build against them are yours — no conversation with anyone required. Mounting an
application inside a matter's route on a deployment the Firm operates is the scoped one, because that route writes to
a Shared Drive folder under a client's matter.
The firm runs applications on that second seam today — practice-specific surfaces, each built for one matter, running on
Navigator at a Project-scoped route with the matter record still in Navigator and the approved output still published to
Drive. That is the worked proof the seam is real.