Version 2 carries an ExecutionPrincipal where version 1 carried an
ApprovalActor. There is deliberately no v1 upgrade path: a run started from
schedule.fire stored the fabricated role: 'operator' that this work
exists to remove, so reading a v1 record back as a human principal would
launder that authority through a migration. validRunRecord rejects v1 and
the run fails closed — a suspended pre-upgrade agent run cannot resume.
Version 2 carries an ExecutionPrincipal where version 1 carried an ApprovalActor. There is deliberately no v1 upgrade path: a run started from
schedule.firestored the fabricatedrole: 'operator'that this work exists to remove, so reading a v1 record back as a human principal would launder that authority through a migration.validRunRecordrejects v1 and the run fails closed — a suspended pre-upgrade agent run cannot resume.