AZ704: A read-only session
The session views as someone else (authz.view_as) or signed in with a token limited by scopes, so it may read but not change anything, sign other people in, view as someone again, or make a key with more scopes than it has.
Reported to the app, by the authz.* functions and the policy's rules: the code is in the error's HINT (rowfence help AZ709), and the SDKs' errors carry it as code.