Local development
Addresses are hierarchical and the hierarchy is enforced rather than conventional. A parameter lives at organization / project / environment / path / name, and that address is the data the ciphertext is sealed against, so a value cannot be read from a scope it was not written to. Staging cannot quietly resolve a production value.
penv pull writes what your app expects and nothing it should not have. Dynamic parameters are the case worth knowing: pull never mints one. It materializes a marker, and penv doctor reports the parameter as runtime-resolved, so an expired lease can never be baked into a local file and shipped.