The shared partner picker (model G — sdk-valuehelp-scoping-v1.0 §1). ONE shape — one
view/controller + one entity-type contract — that hosts N authorized scopes (colleagues,
userAttached, …), each a first-class OData set contributed via #[ContributesScope]. The client
opens openValueHelp({ namespace, scope }); the intent resolves the scope to its set and the
shared view binds it. (Renamed from the scope-specific ColleaguePickerValueHelp — a value help
is a shape, and colleagues is a scope of it, not the shape.)
Carries #[Access] — boundary-scoped gating (sdk-valuehelp-v1.0 D11). Once a picker is
foreign-openable it is the sole open-authorization point: the invoking app's gates say nothing
about whether the actor may browse this provider's people. LocalAdmin — partner browsing
(delegations, on-behalf settings) is a key-user capability. The load-bearing per-scope gate is
each set's own #[Read], enforced at the OData boundary (SD6).
declaredEntityType() is the shape every contributed scope set must project (the
shape-conformance hard gate at sync): id (key), first_name, name.