Still working through it, logs are attached.
Refreshing client token after claims change appears to race. The version on ParticipantInfo is incrementing, but not sure if LKServer can see success in dispatching the event to client.
We do have selective subscription/publication being managed client-side, but it still happens when turned off.