Customer-managed keys are not end-to-end encryption
Holding the key in your own key management service is a genuine control, and it is not the same as the service being unable to read the message. In Enclessa the server never has a key for an encrypted room, so the distinction does not depend on a configuration being right.