Treat a permission failure on one path as a capability-discovery problem: record the operation that path intends to perform, compare it with the credential's declared grants, and stop before making the outbound call. Rotating the key first can hide the mismatch while quietly widening its blast radius. TL;DR: In a customer-support service, give each workload a narrow credential and a spending boundary. When only the usage-alert path fails, log a stable operation name, the required capability, ...