Auth mode and credential payload for this request.
OptionalcallerThe resolved scoped instance's caller-privilege tier (see
ops/CallerTrustTierOps.ts's determineCallerTrustTier()), attached
once the instance is authenticated. Absent until then; assertTrustTierAllowed
treats an absent value as 'full-trust' (see its own remarks for why
that default is safe for every existing, non-browser auth mode).
OptionalrequestOptional caller-supplied correlation id for audit/log stitching.
OptionaltraceOptional request-scoped sink for bounded lifecycle and discovery traces.
Execution-scoped context used to create an isolated Frodo instance.