Project a principal onto the approval-service identity.
Automated principals keep their own id — attribution stays truthful — while
borrowing the least-privileged role so that the approval service's own role
gates (CAN_CREATE, DECIDER_ROLES) treat them as read-only.
Project a principal onto the approval-service identity.
Automated principals keep their own id — attribution stays truthful — while borrowing the least-privileged role so that the approval service's own role gates (CAN_CREATE, DECIDER_ROLES) treat them as read-only.