Extended Reserved Accesses
Documentation status: architecture — see Maturity and evidence.
The Runtime exposes reserved access names in addition to ordinary participant slots. These accesses provide computed or structural information about a node; they are not a generic security/governance metadata mechanism.
The current source-defined reserved surface includes names such as:
Self— the current node;StateIndex— reserved state/index access where supported;NodeType— reserved node-type access;NameandObjectName— Runtime naming projections;FormalName— the stable formal conceptual name;IdandClassId— Runtime identity/class projections;SlotCountandCount— structural cardinality information;Definition— reserved definition access;- together with structural reserved names such as
Me,Context,Kind, andPolyadicMap.
Not every reserved access is populated for every node mode or node kind. Some are computed, some may be unavailable, and some are structural rather than ordinary attributes.
Why these accesses are separate
A conceptual node has normal participant slots, but the Runtime also needs introspection that should not consume domain roles. Reserved accesses provide that surface.
ordinary role access -> modeled participant/value
reserved extended access -> Runtime structural/introspection value
For example, FormalName is a Runtime-level conceptual identifier, while a business field named DisplayName remains an ordinary application role.
Do not model authorization with them
Earlier documentation described extended accesses as carrying visibility or governance semantics. The current engine sources do not justify that generalization. Authorization belongs to the appropriate model/service/security contract unless a specific public feature explicitly states otherwise.
Compatibility rule
Use documented reserved names, not internal negative indexes. Numeric placement is an implementation detail.