jurisdiction_unresolved
No policy set governs this number at all, so there is nothing to enforce and no window can be computed. effective_policy never falls back to a federal floor and never invents a window, because inventing permission on the input most likely to be missing was the original defect. Corrected 2026-08-18: this row read "Fail-closed by CANON fact 74", which ADR-0020 and CANON 143 already amended - the geographic fail-closed rule is gone, and what survives on this axis is a configuration gate. It now means the tenant has neither a jurisdiction set nor a baseline set covering this destination, which is why a configured baseline calling policy is a condition of production activation. Not a synonym for jurisdiction_residual_gate below.
Problem shape
Every non-2xx response is an RFC 9457 application/problem+json body. The type URI below is stable and machine-matchable, so branch on the final path segment (the code) and treat the status as redundant confirmation. See the error-handling guide.
{
"type": "https://docs.vocapable.com/errors/jurisdiction_unresolved",
"title": "…",
"status": 409,
"detail": "…",
"instance": "/v1/…"
}