Extracts the intent, matches against published purposes, evaluates policies, and returns the access decision plus (when allowed) a short-lived intent token.
API key minted at /settings/api-keys. Three scopes: read_only,
policy_write, admin.
Evaluation result.
allowed, denied, pending_approval, approved, shadow_denied "customer_support_lookup"
reporting, export, admin, lookup, analysis, write, other 0 <= x <= 1