ScreeningPreScreenRule
Shared across vendors, since pre-screen reads no vendor signal. when may
be { always: true }, which matches every screen; the post-screen rules
have no such form, so an unconditional rule is unrepresentable there rather
than merely rejected.
Boolean expression over the vendor-independent fields only. Pre-screen
decides whether the vendor is called at all, so it cannot read a vendor
response. Exactly one of always, all, any, not, or a
field/op/value comparison.
always is accepted only as a rule's whole condition, never nested, and
only in preScreen — which is why it is declared here and not on the
vendor rule nodes. Anywhere else is a 400.
Whether the paid vendor call happens. SCREEN when no rule matches.
SCREEN, SKIP