OptionalmessageMessage envelope (plain string, or the resolvers' JSON {resolver,type,status,data} shape).
Authenticated user the operation belongs to (the trust anchor the filter enforces).
Session the target client subscribed on (routes the push to the right browser tab).
Parameters for publishStatusUpdate — identity (
ownerUserId) is required by design.