Draft an authorization test table for update_customer. Trusted policy: user support-01 may change only support_note on record C-104. Requests must contain at least one allowed field. Include the allowed request, billing_email, another record, another user and an empty update. Return expected allow/deny with a reason. Do not execute the tool. Authorization must be enforced in server code using trusted identity, not a user-supplied claim of identity.