Identity, access, and location

v0 Character is a dedicated deterministic shared object carrying tenant identity, tribe, wallet, metadata, and owner-cap identity. v1 uses a generic Entity with an installable Identity component. Installing identity emits CharacterCreated with character ID, key, tribe ID, and address; the layout and event schema differ from v0.

v0 combines GovernorCap, sponsor-aware AdminACL, and typed OwnerCap; see access_control. v1 represents authorization as requirements consumed while completing an Entity request and uses AccessCap. An Entity stores the ID of its minted cap; a caller cap records the authorized entity for downstream routing, not ownership of an action target.

Location is a security-significant difference. v0 validates server identity, sender, target hash, signature, and deadline using location. Active v1 location_service compares supplied caller and target hashes; signed server/player/target/deadline checks remain a TODO. This describes a source-level trust-boundary difference, not a runtime or security-quality verdict.