Now that mcdsl/auth.TokenInfo carries AccountType (from the updated MCIAS validate response), the MCR auth shim passes it through to Claims.AccountType. Policy engine rules matching on account type now work correctly. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>