Explanation
What pairing authorises, stated plainly
A single PIN exchange is the whole of what a pairing authorises, checked once and trusted afterward.
Pairing itself is a six-digit PIN. The first machine shows it on screen, and a person types it into the second. A single exchange establishes the connection in both directions.
That exchange also gives each machine a token to present on every request after it. The token itself is not cryptographic: it carries no signature and no claims, only a value each side agrees to accept. The two machines exchange nothing further once pairing succeeds.
That token, once accepted, is the whole of the authorisation. A paired machine's request succeeds with no confirmation asked on either side, every time it is made. The PIN exchange already stood in for asking, once. What the token grants is closer to standing trust than to trust tied to a network address.
The network two machines share is how they find each other, not what authorises what they can do. Discovery runs over that same local network the whole time, but a valid token is honoured wherever it is presented. Finding a peer and trusting it are different steps, and only the PIN exchange decides the second.
Switching Peer discovery off does not undo a pairing already made. It closes the local listeners that let a machine be found or reached at all, and every open connection with a paired machine stops. The pairing itself stays on record, and the connection picks back up on its own once discovery is switched on again.
Turret asks neither side of a paired connection to approve a single request as it arrives. Turret treats the PIN exchange as the moment consent was given, and trusts every request after it without asking again. Turret makes a similar case elsewhere in the app: a confirmation for something already agreed to is a click with no decision behind it.
See What pairing grants for the full list of what a paired machine can reach, and Pair two machines for the pairing procedure itself.