OptionalcanonicalOptionalcanonicalSession identity only; without explicit storage or a per-call filesystem this grants no filesystem access.
Authoritative UAM project. Use BackendRuntime.openSession() when importing an existing project from storage.
OptionalsessionOptionalstorageOptional writeback target for the authoritative UAM project; this is not an import source.
Host-defined session identity; not a filesystem authorization or an allowed-root override.