923960fa4b
Follow-up to the salvaged #111004 commit, aligning it with the shape agreed on #110995: - Drop the HERMES_KANBAN_DISPATCH_PROFILES env bridge: non-secret behaviour lives in config.yaml only, like every other kanban.* key. - Read the key via load_config_readonly() with the same fail-open config read as the sibling kanban.* readers (configured_max_in_progress). - Fail closed when the key is set: the "none" sentinel is gone (an empty list already claims nothing), and an assignee that is not a valid profile id is never claimable instead of being lower-cased into the allowlist. - Trim the regression file to two invariants (allowlist without `default` buckets the card as nonspawnable AND turns has_spawnable_ready off; unset key keeps upstream behaviour). Both drive the real dispatch tick against a real config.yaml + kanban.db; the first is red on origin/main. - Docs: move the "Shared boards across homes" section out of the gateway-dispatcher paragraph, state that `default` collides by construction, add the config-reference row.