The caller-scoped provider list now reduces each provider's models
through the same effective computation the setup answer and the proxy
use: allowlist guardrails intersected with the operator's declared
models, with bare entries synthesized when the operator declared none.
The dashboard's model filter therefore never offers a self-scoped caller
a model their own requests could not use. Grant holders keep the full
declared lists — their usage view spans everyone's requests, and their
own setup page already answers with the caller-scoped effective set.