fix architecture.md: update moderation policy
!no-unauthenticated is not filtered — it applies to content, not
identity. only bluesky mod service labels (!hide, !takedown, spam)
hide actors. also removed stale ingester description about detecting
!no-unauthenticated self-labels.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>