On create (POST): a value of INTERNAL from any caller outside DriveWealth is silently treated as EXTERNAL - no error is raised, unlike the GET list filter's 403 for the same case. On edit (PUT/PATCH): this field is not honored at all - a note's visibility is fixed at creation and cannot be changed by editing it, for any caller.