Use when
- A signed-in user lacks permission to view, edit, publish, export, delete, approve, share, administer, or configure a resource.
- A wrong account or missing team membership is a likely cause.
- An access request, owner approval, switch-account flow, or read-only fallback can help the user recover.
- The product needs to communicate least-privilege and policy boundaries without making the state look like a system outage.