The sweep and bot-state comments still said room member sessions are hidden
through a core session.set_hidden RPC; the code hides them through the source
primary's REST PATCH /api/sessions/{id} via host.setPersistedSessionHidden
(a 404 prunes the seat). Comment-only.