Revert to exception-based policy errors, add "secure" flag to policy to track authn.