9dea289975
SEND covered three different call shapes under one action (local sessionId delivery, the coordId cross-host broker route, and the turnId answer-a-blocked-worker form). READ covered both roster/ profile/identity observation and ticket-polling/session-status. Split each into its own Authz.Action — SEND/COORD_SEND/ANSWER and READ/TASK_READ — with every new action granted to exactly who held the combined action before, on both the MCP and REST entry paths. Also fixes fleetd #678's Authz.java comment: READ no longer claims "the roster carries no secrets" for ticket replies and pending questions, because those now live under TASK_READ.