{ kind: 'read', query: { family, limit, cursor? } } under owner or current READ-agent authority. Reads commit no financial change and spend no accepted-order budget.
Nonzero cursor is revision[32] plus permitted-row offset u64 big-endian. Permissions filter rows before paging. Changed rows cause encrypted conflict; discard the old traversal and restart at zero. Do not splice revisions. Reconnection signs under a new binding/current authority; obtain a fresh zero-cursor snapshot.
Revision excludes unrelated users’ commits and global journal sequencing. Retention is bounded; journal exhaustion contains rather than silently pruning. End-of-pages is not proof of complete external venue history.
Missing/unqualified fields are absent, not zero. committedAt/observedAt are qualified Cinder clocks, not invented exchange execution or block timestamps.
Checked SDK excerpt
family is a documented ReadFamily; ctx/client have the same configured meaning as on command pages.