You'll notice
An org network-policy refusal from the artifact gateway is now reported clearly instead of as a generic upstream failure.
When the artifact/session gateway responds with a 403 and a specific network-policy-denied body, the client now recognizes it as a distinct case rather than a generic upstream failure: telemetry records the relay_policy_refused outcome, the result carries gatewayPolicy: "network-off", and the user sees a clearer message explaining that organization network policy denies artifact storage reads for this session.