Refused by the page register
Identity and tenancy is closed to this session
/identity carries a declared floor of Function Leader. No session is signed in, so no role is held at all and the floor cannot be cleared. This is the whole rule, stated here so that it does not have to be discovered by trial.
what this page does
Identity
The page names who may sign in and which tenant they belong to.
declared floor
Function Leader
The same floor is held on POST /api/tenancy/probe, so the control and the page it lives on refuse at the same line.
what this session holds
No session
Signing in is what produces a role. Until then there is nothing to compare with the floor.
Why this route carries a floor
Taken word for word from the page register, which is published in the open.
The page names every account that may sign in, the role the directory gives it, the tenant it belongs to, and where the boundary between the live estate and the sandbox sits. It also carries the tenant probe, whose endpoint was already floored at the function leader. An account roster is the one read on this platform that is worth more to somebody who should not have it than to somebody who should.
What to do about it
Sign in and the role is read from the account record. If the account behind it still sits below the floor, this same screen appears again with the role named.