diff --git a/.changeset/21174-admin-audit-metadata.md b/.changeset/21174-admin-audit-metadata.md index 5b76956c8bb..f9a8d2baa17 100644 --- a/.changeset/21174-admin-audit-metadata.md +++ b/.changeset/21174-admin-audit-metadata.md @@ -10,4 +10,4 @@ The admin create-user and set-user-password endpoints each write their own `sys_ The explicit row now carries only the admin's decisions — which operation ran, whether the password was generated, whether the account's address is a generated placeholder, whether the membership was bound and to which organization — plus its reference to the user (`object_name` and `record_id`). The values the call writes into the user's fields are recorded where they already were: on the mirror's `create` and `update` rows for those same writes, in the snapshot columns the read side narrows per reader. The decision set is a closed type, so a field value no longer compiles into the row. -Migration: a reader that took a user field's value from the explicit row's metadata reads it from the mirror's row for the same write instead (its after-snapshot), served according to the reader's field access. Rows written before this release are stored data and are not rewritten. +Migration: a reader that took a user field's value from the explicit row's metadata reads it from the mirror's row for the same write instead (its after-snapshot), served according to the reader's field access. Rows written before this release are stored data and are not rewritten. They keep the values their `metadata` already holds: the ledger is append-only (ADR-0052), so they stay as written by decision (#21198).