Authorization Decisions
Authorization is not execution.
Policy decision: ALLOW / REQUIRE_APPROVAL / DENY Execution status: AUTHORIZED → PROCESSING → COMPLETED | FAILED | EXPIRED
Paymod returns ALLOW, REQUIRE_APPROVAL or DENY. The persisted intent uses AUTHORIZED, WAITING_APPROVAL or DENIED to represent that result before execution begins.
ALLOW may proceed. REQUIRE_APPROVAL holds the reservation and waits for a human where that flow is available. DENY cannot be bypassed by approval. An authorized payment can still fail or become unknown downstream.