Any GroupRef. Bare contacts labels are normalized to
contacts:<viewerPlayerId>:<label> at the verb boundary; the two
reserved pseudo-subjects everyone-else / strangers are stored as
their bare reserved identifier (they are not GroupApi refs).
One policy row in a viewer's ordered notify list.