USER controls (via sy_auth_*):
├── Username (set once, immutable)
├── Settlement chain + token + destination
├── API key regeneration
├── Vault deployment + activation
└── View own sessions, ledger, settings
PARTNER controls (via sy_secret_*):
├── Create sessions targeting accounts
├── Create deposit addresses
├── Submit tx hashes on their sessions
├── Refund/cancel sessions they created
└── Webhooks for events on their sessions
NOBODY controls:
├── Primary wallet address (immutable, set at creation)
├── Account ID (auto-generated, never changes)
└── Partner assignment (account belongs to one partner)