admitRecord
Point-read admission of record, the snapshot-shaped record of a state that selection chose (by id; a tracing read also states its deletion scope), under the subscriber's entry and scope.
Step 0 accepts the entry and, when the entry policy says so, requires an authenticated scope against schema's profile (the snapshot profile without one), as a query route does. Steps 2 and 3 then run on a QueryType.SINGLE query of selection: the caller's scope and every QueryPolicy restriction are appended, then the snapshot model's default scope. There is no submitted query to budget or rewrite, so the budget and step 1 do not apply. The resulting filter is put in canonical form (aliases replaced when schema is given, EQ/NE of null lowered, logical nodes simplified) and evaluated on record in memory with the semantics of the filter semantics matrix; an operator the evaluation does not support fails closed.
Emits record masked by schema's response masks, or nothing when the caller may not read it. Policies need the schema, so a read with policies fails when schema is null.