* use 403 for authorization error * update silences API * add ForbiddenError to rule API responses
kind
attribute
identifier