Read-only users will soon be able to open the transcription read view, so the write endpoints become the real authorization boundary. Explicitly assert a READ_ALL-only principal is forbidden from create/update/reorder/ review block writes and annotation create/patch (the prior tests only used a no-authority principal). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>