withQuerySelection
Appends a route selection: what a load route names in its URL, the aggregate id, a version range, and the tenant and owner its path carries. It is an operation constraint, not caller scope: admission appends it at step 2 with the caller scope, after every QueryFilter, so a rewrite can neither see nor remove it, and it is neither budgeted as scope nor reported among the audit's scope fields.