Keep authorization errors actionable
# Keep authorization errors actionable
Validate the requested harness against the server registry and its enrolled membership. Return a bounded authorization error for unsupported or unenrolled families, while reserving server errors for infrastructure failures. Keep credential, scope, mode, epoch, quota, and ownership checks unchanged.