Report Access
A member's access to a report = isReportAllowed: source ∈ allowed_sources and account_ids ⊆ allowed_accounts (if set).
There's no separate "personal / workspace / Admin" matrix layered on top of owner/member in the source of truth — scope is what cuts it.
The owner sees all reports in the workspace.