[Official Endor Labs SDK docs (troubleshooting.md)]: For endpoints that take a resource UUID in the body and a namespace in the path (for example create scan-log-request with scan_result_uuid), the path namespace must be the owning namespace of that resource, not a parent. Validate with `endorctl` using the owning namespace from the resource row. Related 404: when you act on objects returned from list(traverse=True), pass the resource object itself to get/update/delete (for example client.Project.delete(target)) so the SDK uses the resource's tenant_meta.namespace; using the client default namespace causes 404 Not Found.

Context: Official docs (endorlabs-sdk troubleshooting.md): documents the namespace-scoping gotcha that trips agents when an endpoint takes a resource UUID in the body and a namespace in the path. Passing a parent namespace errors even with a valid UUID; the path must be the owning namespace (tenant_meta.namespace of the resource).