A production rollout exposes a contract mismatch between the UI boundary and the owning service. The affected area is API transaction.
Repair the API transaction access policy implementation so it returns only permitted actions and explicit denial reasons.
Evidence
- Affected surface: Full-stack backend focus / API transaction.
- Observed failure family: enforce permission rules.
- Scope policy: tenantId must equal tenant-primary.