Validate an untyped candidate into an ApprovalActor — the ONE place a decoded token/map entry becomes an identity. No as-casting at the JSON boundary: id non-empty, role recognized, tenantId pattern-valid and not a reserved identity.
as
Validate an untyped candidate into an ApprovalActor — the ONE place a decoded token/map entry becomes an identity. No
as-casting at the JSON boundary: id non-empty, role recognized, tenantId pattern-valid and not a reserved identity.