Set when the user's trust policy could not be read (fail-closed).
Non-None even on a successful resolution — user-level configs and any
DANGEROUSLY_ENABLE_PROJECT_MCP_SERVERS env names still load, but scoped
project approvals were discarded. Surfaced so the read failure is never
silently swallowed just because some other config remained usable. See
ConfigResolutionError.policy_error.