Declaration is not authority
An application graph can declare the permissions it expects, but that declaration does not itself grant runtime capability. Authority is provided outside the graph by the execution environment.
Fail closed
A state-changing action that lacks required runtime authority should fail rather than interpreting the graph's requestedPermissions field as self-authorization.
Why this separation matters
It prevents generated structure from escalating its own privileges merely by adding a permission identifier to the document it generated.