Only the ones aimed at /consumer-profiles itself. Top-level create, PATCH, and DELETE all mutate real state — a renamed profile stays renamed, a deleted one 404s. The sub-resource routes are theater by comparison: they accept any body and answer the John Doe fixture, whose profile id doesn't even match the one in your path — the giveaway that nothing was written. Adding an address, then re-reading your profile, shows the addresses array still empty; assert sub-resource contracts against the fixture and profile state against your own minted record.