Parent epic: channel settings and shared channel authority.
Problem
Group channels currently report No shared workspace, while each agent lane may still have an internal sponsor workspace. There is no canonical channel binding that makes every participant's execution context unambiguous.
Scope
- Add a canonical zero-or-one shared-workspace binding from a channel to an active channel-scoped workspace grant.
- Add owner/admin bind, replace, and clear operations with concurrency and replay safety.
- Resolve the binding for every attached or standing agent lane before execution.
- Verify runtime/OS accessibility per lane and expose bounded readiness reasons. Never silently fall back to an agent sponsor's private workspace when a channel binding exists.
- Define the safe behavior when no binding exists: neutral channel execution with an honest UI state.
- On binding changes or revocation, stop/invalidate affected live processes and provider sessions at a safe boundary, then rebuild context against the new workspace.
- Record workspace identity/revision in context manifests without leaking protected paths.
- Add runtime, continuity, restart, and revocation diagnostics.
Acceptance criteria
- All successfully executing agent lanes in a bound channel use the same canonical workspace identity.
- An inaccessible lane fails closed with a precise readiness error and does not execute in a fallback directory.
- Switching or clearing the binding never changes a principal's default workspace.
- Existing direct-message workspace selection remains principal-owned and unchanged.
- Installed qualification covers two principals, multiple agents, binding replacement, revocation, restart, and absence of path leakage.
Parent epic: channel settings and shared channel authority.
Problem
Group channels currently report
No shared workspace, while each agent lane may still have an internal sponsor workspace. There is no canonical channel binding that makes every participant's execution context unambiguous.Scope
Acceptance criteria