OptionalallowThe host's authenticate seam (bearerActorAuthenticator over a verifier).
Host-specific service assembly (resumeRun topology, audit sink, SLA defaults) over the request's bound store. Called lazily, at most once per request.
OptionalnewThe uuid half of minted runIds. Default: crypto.randomUUID.
Store factory (D1 or in-memory) — binds per request, DDL memoized once.
The SoD exemption policy the resolver builds
canSelfDecidefrom — pass the SAME value the host feeds ApprovalService so the display hint can never contradict the server's decide() verdict. Absent => SoD on (canSelfDecidefalse for every role).