Return a sealed review submission to the author (OPD-130)
Marks a sealed submission RETURNED against a CORRECT_AND_RESUBMIT review record, so the agent that authored it can read the record under its capability and seal a revision that answers it.
A human governance act (ADR 0003). Only a verified human-session principal is admitted. A credential that holds policies:write but is not a human session is refused 403 HUMAN_PRINCIPAL_REQUIRED; one that does not hold policies:write is refused 403 FORBIDDEN by the scope gate first, before the human check is reached. Two controls, two codes — neither renders as permission.
Who may. The human whose session recorded the named record (recording_reviewer), or a tenant admin as the ruled FALLBACK (tenant_admin). Anyone else receives 403 REVIEW_RETURN_NOT_REVIEWER_OR_ADMIN. The fallback is ANY tenant admin — it does not mean a named second reviewer, and nothing checks that the admin read anything. return_authority records which door was taken.
The record must be a CORRECT_AND_RESUBMIT of THIS submission. Another disposition is 409 REVIEW_RECORD_NOT_CORRECT_AND_RESUBMIT; a record that is not on this submission (or does not exist, or belongs to another tenant) is one 404 REVIEW_RECORD_NOT_ON_SUBMISSION covering all three, deliberately, so the route is not an existence oracle.
Once. The machine is SEALED → RETURNED; a second return is 409 REVIEW_SUBMISSION_ALREADY_RETURNED.
What it changes and what it does not. One append-only return row and one review_submission_returned audit row, on the same transaction. The sealed subject is untouched, the authoring capability stays valid, and the shell version stays draft.
RECORDS that this human under this authority returned this subject naming this record. It does NOT establish that the author saw it, that the record is correct, or that anything was corrected. It is not a receipt and nothing here is signed.
Authorizations
MeshQu API key passed as a bearer token: Authorization: Bearer mqu_…. Mint one in the console (Settings → API keys).
Tenant UUID for multi-tenant isolation. Required on all authenticated routes — validated before authentication (middleware/tenant.ts), so a missing or non-UUID header returns 400 (MISSING_TENANT_ID / INVALID_TENANT_ID) before the API key is checked.
Path Parameters
The sealed submission id. This is the review IDENTITY — not the policy version, which is a mutable container that yields many sealed subjects over time.
Body
The CORRECT_AND_RESUBMIT record this return acts on. It must be a record of THIS submission and its disposition must be CORRECT_AND_RESUBMIT; anything else is refused rather than returned under a disposition that did not ask for a revision.
Response
Default Response
RETURNED recording_reviewer