The client is transport, not authority
This is the part that decides whether everything above it is real. When an agent reads a policy, rewrites it into its own config format and then enforces that, the signature covers the document that arrived rather than the thing that runs. Whoever can reach the config file of that agent has just become the policy author.
Here the bytes that get checked are the bytes that were signed. The client relays them verbatim to a system service, and that service verifies against a pinned key. It is a quiet failure mode in plenty of security policy management, and it is worth being fussy about.