Remove pre_approved_agent_privileges from FoundationalFlow
What does this MR do and why?
Ai::Catalog::FoundationalFlow carried two privilege attributes: agent_privileges and pre_approved_agent_privileges. Foundational flows run with no human in the loop, so that split doesn't apply - whatever privileges a flow uses are effectively pre-approved already. Every flow definition had to declare pre_approved_agent_privileges, and the model carried fallback logic that copied it into agent_privileges whenever the latter was left empty.
This MR drops pre_approved_agent_privileges from FoundationalFlow and its per-flow definitions; flows now declare agent_privileges directly. CreateAndStartWorkflowService still populates both agent_privileges and pre_approved_agent_privileges on the Ai::DuoWorkflows::Workflow record it creates - that model also serves human-in-the-loop workflows, so it keeps its own separate pair of attributes.
References
Follow-up of !249586 (merged).
How to set up and validate locally
bundle exec rspec ee/spec/models/ai/catalog/foundational_flow_spec.rbbundle exec rspec ee/spec/services/ai/duo_workflows/create_and_start_workflow_service_spec.rb ee/spec/services/ai/catalog/execute_workflow_service_spec.rbbundle exec rubocopon the changed files
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.