Describe AuthorizeBatch semantics (all-or-nothing, single-entity-type, single-organization, batch attribute requirement, audit logging), the authz.NewBatchAuthorizeFunc / WithBatch* helpers, the MCP Resolver.AuthorizeBatch entry point, and the new batch-style AuthorizationAttributes implementation contract (non-empty, deduplicated, same-entity-type input; only found rows returned). Signed-off-by: Bryan Frimin <bryan@probo.com>