### P1. Push/pull transfer file set — SETTLED (Credentials + Metadata)
Transfer `auth.json` (cookies, tokens, session identity) and `metadata.json` (plan tier, spend watermarks, profile label). Ephemeral caches, runtime logs, and local locks are omitted from transfer. (`profile.json` in the earlier grill options was shorthand for this file and is superseded; confirmed 2026-10-07.)
### P2. Live-session switch guard — SETTLED (Block with Force Override)
Refuse to switch credentials if active `muse-bin` or worker processes are detected holding the old profile identity. Operators must either terminate active processes first or explicitly pass `--force` to override, preventing mid-stream 400 outages caused by stale in-memory tokens. (Confirmed in this interview 2026-10-07.)
## Pending
None. (All pending architectural decisions P1 and P2 are settled).
## Session credential isolation (P3 — BUILT 2026-10-07, user-ordered)
Each muse session runs with an isolated config dir
`/tmp/muse-session-<pid>/muse`: symlinks to `~/.config/muse/*` except
`auth.json`, which is replaced with the bound profile's credentials;
refreshed tokens sync back to the profile on session exit/save.
Implications (unresolved): this largely obsoletes P2's block (switching
stops disturbing live sessions; the guard becomes a backstop for
legacy non-isolated sessions). Open risks: token sync-back races when
two sessions share a profile (solved: newest-wins by mtime),
sessions killed -9 never syncing (solved: reap-by-scan, no exit hook),
symlink fragility (accepted: rebuilt per launch).
Implementation: bin/muse_session_bind.py (`launch` builds the dir and
execs with XDG_CONFIG_HOME; `save`/`reap` sync back; `status` lists).
Key integration choice: exec, not supervise, so panes keep their
muse-bin identity and watcher coverage is untouched. Tests:
tests/test_muse_session_bind.py (13). Follow-ups for the owning lanes:
wire `box runtime launch` / resume-pool `resume` through the binder,
and arm a reap timer once the profile store (P1) exists.