shadow and dream name separate owner-scoped checkpoints; they do not grant extra permissions. Every item returned by sessions review still needs examination, including the final page where has_more is false.
revision and content_revision plus last_reviewed, the pair previously examined for that role, if any. A new item or changed content calls for reading the exact current pair. A metadata-only change can be assessed from current metadata and linked work while reusing history already examined; read messages again if the change needs them. review-read starts with recent messages, each page chronological. Use its returned next_before_position with --before for older messages, or --order oldest --after POSITION to page forward. Its default history includes current and earlier saved messages. The next_cursor from review is informational; it is not a CLI argument.
After processing the current page, request the next page if has_more is true. When it is false, finish this page before stopping. Mark only the exact pair examined with reviewed; an older pair leaves a newer change pending. A session_revision_conflict means the session moved, so obtain the new pair and reassess. Reviewing may result in no edit or user message, but reading alone does not advance the checkpoint. This is different from acknowledging a provider notification, and neither operation starts an agent run.