Return managed settings whose declaration cannot be safely applied.
A key is a violation when an enforced managed policy declaration cannot be
applied, when a known managed section has a non-table value, or when a
managed [models] default, recent, or auto-classifier value contradicts a
managed models.allowed list. The shape cases matter because "wrong shape"
is not "absent": merging such a value can erase a user subtree before a
reader falls back to a default.
That last case is the only one that reports a key which is not itself in
ENFORCED_MANAGED_KEYS (models.default, models.recent): the value is
individually valid and merely inconsistent with the administrator's own
ceiling, which would otherwise start a session whose pinned model the same
policy forbids.
Required rather than defaulted to the process snapshot: managed_health
pairs this with the health of the same snapshot, and a default that
silently read the cache is what let a refreshed status be reported next to
stale violations.
Managed table to inspect. Must come from a snapshot whose
status is usable, since an unhealthy snapshot carries {} and
would report no violations.
Health and display metadata for the same managed snapshot.