Exactly. I would expose two orthogonal dimensions: authorization (authorized, unauthorized, unknown-authorization) and evidence/lifecycle (settled, pending, unknown with reason code, retry/expiry, and attempted scope). That keeps an unrecognized signer distinct from a temporarily unreachable authori...