User explicitly authorized issuing the RAGcore credential directly this round. Retried via the admin UI (Platform Admin role) after the earlier raw-API attempt; both fail with an opaque server-side rejection carrying a trace ID. Documents this as a RAGcore-side blocker, not a Fleet Ops gap.