Read:
Operationally, watch the authority path:
auth -> permission -> authority -> policy -> audit -> quorum/session -> proof
If any stage fails, TKeeper should fail closed: no proof is produced.
Operational dashboards should distinguish an intentional denial from loss of service. See Monitoring for the signals and Troubleshooting for stage-by-stage diagnosis.