PE3 — catalog↔class agreement. The MJ: Permission Domains row DECLARES the domain's
capabilities (SupportedActions, SupportedGranteeTypes, SupportsDeny) and the provider
class RESTATES them as readonly members. Admin UIs read the row; runtime code reads the class.
When they disagree, the UI offers a grant the provider will never honor. Drift detector.
PE3 — catalog↔class agreement. The
MJ: Permission Domainsrow DECLARES the domain's capabilities (SupportedActions,SupportedGranteeTypes,SupportsDeny) and the provider class RESTATES them as readonly members. Admin UIs read the row; runtime code reads the class. When they disagree, the UI offers a grant the provider will never honor. Drift detector.