A cross-layer workflow passes unit tests but breaks when client, API, and persistence state arrive in a different order. The affected area is session boundary.
Repair the session boundary access policy implementation so it returns only permitted actions and explicit denial reasons.
Evidence
- Affected surface: Full-stack frontend focus / session boundary.
- Observed failure family: enforce permission rules.
- Scope policy: authorized must equal true.