Every other ModelPickerView callback (provider/model select, expensive confirm, back) runs through the shared _HermesView._gate auth check, but _on_cancel did not. A non-allowlisted member could tap Cancel on the owner's picker, marking it resolved and clearing the view. No model switch was possible, so impact is low, but the gate should be uniform. Reuse the same _gate call the sibling handlers use.