local-first · v0.1

Broker policy profile mismatch

Broker decision — HOW is this authorized request brokered? Fail-closed verification of the ApprovalToken, capability plan, BINDING policy allow, vault references, and scope binding. A single-use grant is issued only on brokered; it authorizes nothing to execute here — only the future Provider Execution runtime (V4) consumes it.

deniedbinding: trueno consumption0 vault refs#4c23a50e
approval token:apptoken:appr-dev-allowbinding policy:policy:eval-research-allowcapability:capperm:emb-a-reason

Verification reasons (fail-closed)

policy_profile_mismatchdeny
policy profile "default-enforce" != plan policy profile "restricted-analyst"

Broker grant & provider handoff (V4 readiness only)

No grant — the request was denied (fail closed). Nothing to hand to the Provider Execution runtime.

Request inputs

execution reasonbroker brk-policy-mismatch
consumed approvalappr-dev-allow
binding policy ref (M41)policy:eval-research-allow
execution intent (M50)
brokered at ordinal100