A production rollout exposes a contract mismatch between the UI boundary and the owning service. The affected area is account settings.
Repair the account settings access policy implementation so it returns only permitted actions and explicit denial reasons.
Evidence
- Affected surface: Balanced full-stack / account settings.
- Observed failure family: enforce permission rules.
- Scope policy: tenantId must equal tenant-primary.