Same refresh seam as the platform. Under the hood both sources implement
PolicySource.fetch(); the agent runtime calls it at the top of every turn and
only swaps the active policy when the returned bundle is a new instance.
Unchanged → identity match → no work. That’s the same hot-reload path
hexgate serve uses for platform-edited YAML.