Resolves #3 (3mw7qfm4slh22).
Scope the revision-checked work ledger by the session's canonical workspace, consistently across human /work, Python/remote work RPC, and CRUD. Cross-workspace get/update/delete and parent assignment fail closed. Existing global rows are retained in a reserved legacy scope instead of exposed to unrelated workspaces; recovery instructions are included. Migration adds cwd before creating its index, including on existing databases.
Verified by manager in isolated worktree: gleam format --check src test; gleam test (109 passed); python3 test/e2e/run.py work_test.py (1 passed); python3 test/e2e/run.py extensions_test.py:ExtensionTests.test_work_command_is_scoped_to_each_workspace (1 passed).