OptionaldeploymentWHO is executing. On an approval resume this is the restored original principal, never the reviewer who decided — so a human approval does not transfer that human's authority into the resumed run.
The server-resolved permissions this execution runs under, projected into
derived request context as breakwater.principalPermissions on every
leg. null when no resolution exists — no resolver configured, or the
resolution failed on an agent that requires no permissions. The null is
projected explicitly rather than omitted so a resume leg retires any
stale persisted projection instead of inheriting it.
OptionalsafeNon-reserved context accepted only from trusted internal entry paths. Public HTTP agent starts never populate this field.
Infrastructure-verified deployment tag for audit attribution.