AxonFlow System Policies API
System policy management (ADR-019), served at `/api/v1/system-policies`. Pattern-based enforcement rules for SQL injection detection, PII detection and similar checks, resolved across the system, organization and tenant tiers. **v11: writes to this family are refused by the legacy policy freeze.** `migrations/core/172` makes `static_policies` read-only to the application roles, and create, update, delete and the enabled toggle write that table. On a deployment whose connection is an application role (the agent's default) those writes are refused with `409 LEGACY_POLICY_WRITE_FROZEN`, the answer the orchestrator gives for its own policy writes (see `policy-api.yaml`). Its `error.code` is that string, where the other errors on these routes carry the numeric status. Author policy through the typed authoring route, `/api/v1/typed-policies` in `orchestrator-api.yaml`. Reads, the pattern test, and the per-policy overrides - which are stored in their own table - are unaffected. A deployment whose connection may still write the table (the database owner; a property of the connection, not of `AXONFLOW_DB_USE_APP_ROLE` alone) is not bound by the revoke.