A production rollout exposes a contract mismatch between the UI boundary and the owning service. The affected area is auth session.
Repair the auth session access policy implementation so it returns only permitted actions and explicit denial reasons.
Evidence
- Affected surface: Full-stack backend focus / auth session.
- Observed failure family: enforce permission rules.
- Scope policy: cohort must equal stable.