You'll notice
No documentation found
If a session rule no longer covers a call after approval, it is refused with a distinct approval_no_longer_covers code.
If a session-rule re-check after an ask-first approval no longer matches the previously-granted rule, the call is now refused with a distinct approval_no_longer_covers error code and message instead of the generic denied-by-session-rule path.
Names in the bundleapproval_no_longer_covers