Harness enhancements

The desktop harness (apps/harness/harness.mjs, 99-line zero-dep watcher) is the "credentials stay on your machine" local capture path: watch a folder → POST images to /api/harness/ingest → review queue. It's the cheapest high-volume on-ramp for a seller's existing photo workflow. Enhancements, prioritized.

Tier 1 — make it trustworthy at volume (pain #4 photo throughput)

Tier 2 — privacy & safety (the whole point of "stays on your machine")

Tier 3 — operator experience

Tier 4 — reach

Sequencing

Identity + idempotency (Tier 1) align with Wave 4 (P5 connectors / P9 API). Privacy guards are the P5 quarantine condition for /api/harness/ingest (already tracked). Operator experience + packaging are independent and can ship anytime once the contract path is live.