Audit Fail-Closed
Audit persistence failures block allowed evaluations.
If audit write fails after an allowed policy evaluation, the API returns 503 audit_persist_failed instead of the evaluation result. This ensures no allowed action proceeds without an audit record.