"Denied" is not an answer. "Not the owner of this record" is.
Most permission layers we inherit return a bare False, so nobody can tell a missing role from an ownership rule, and the admin quietly grows a second copy of the same logic. One rule set, one explanation, in both places.
When a user pings support about a 403, your system should be able to name the rule that denied them. https://shipmindlabs.com/c/824eabe2