ctrlrun.IdentityError — class, defined at src/ctrlrun/errors.py:194
ActionDenied: an agent loop’s except ActionDenied is written to handle a policy
saying no, and a credential that stopped being valid is not that — the same distinction
v0.1 §5.1 draws for EffectKeyError. A missing principal stays
ActionDenied(reason="no_principal"); this is for one that was produced and found wanting,
which includes an expired Principal reaching Control.execute (§2.3).