OptionalonCalled (once per request) when a renewal observes CancelRequestedAt set.
OptionalonCalled (once) when a renewal discovers ownership has been lost. The engine uses this to abort the in-flight sync locally; writes are additionally fenced at every batch boundary, so this is fast-fail, not the safety net.
OptionalprogressSupplies the latest progress JSON to piggyback on each renewal write.
Options for the background heartbeat started via RunOwnershipService.StartHeartbeat.