The verifier refuses, and the refusal names the constraint that was exceeded rather than returning a generic failure. The chain can be entirely valid and the action still refused — those are different results and the wire format represents them differently.