A distributed workflow needs a localized repair without weakening observability or rollback safety. The affected area is audit pipeline.
Repair the audit pipeline access policy implementation so it returns only permitted actions and explicit denial reasons.
Evidence
- Affected surface: Full-stack backend focus / audit pipeline.
- Observed failure family: enforce permission rules.
- Scope policy: contractVersion must equal 2.