Fingerprint durable access policy plus workspace identity.
Covers the trust/tool/sandbox/approval payload (the
to_workspace_payload() keys) and the workspace's cwd/project_root.
Cosmetic model settings (MODEL_COMPATIBLE_FIELDS) are excluded so a
model switch does not invalidate a durable binding; runtime-only fields
(RUNTIME_ONLY_FIELDS) are excluded because they are not persisted.