Optionalnotice: Record<string, any>
the directory's account observer notice: username and
kind (updated, with the attribute maps before and after, or
membership), or a notice that already names the moved claims
{ claims }, or null when nothing a token carries moved
Works out the claims a directory write moved, in CAEP token-claims-change's shape: each changed claim with its new value, and null for one that is gone.