Patch a policy's identity fields (NOT its config — that's a new revision).
scope is intentionally NOT here: it is an identity-level fact set ONCE at create (spec §2 — moved off the revision to Policy, server_default='attachable', with no update path). Allowing it on PUT would advertise a mutable field the service silently drops; organization-vs-attachable is decided at authoring time, so it stays immutable post-create.
Successful Response