the signed-in person
their sign-on session
the waiting row
{ approve, ticked, subject }, and (#432 phase 5)
req, the portal's request, and form, how its posted limit
controls are read (common/limits_form.ts)
{ ok: true }, { ok: false, stepUp: true, ask } when the
session falls short, or { ok: false, why, code }
Records the owner's answer from the portal: the rights they left ticked, held to the step-up they need, then the grant engine's decision. Once across the cluster.