OMP Workbook

Read the source. Follow the evidence.

Orientation

A tool call can stop without offering a dialog. Another call can run without asking, even in a mode named always-ask. A call displayed as write can actually dispatch a different tool, with a different tier and policy key. None of these observations is explained adequately by saying that permissions are simply on or off.

This part teaches an operator’s method: identify the exact operation, follow the policy that applies to that operation, and distinguish permission to proceed from evidence of an effect. You will read enough TypeScript to understand the decision, but you do not need to build an extension or make a provider request.

The practice setting is the fictional Cedar Seed Library. Its three desks are a sequence of reading exercises:

  • Approval Desk classifies declarations, modes, policies, and ordered shell rules.
  • Dispatch Desk follows an operation through a write envelope into an argument-sensitive device tool.
  • Boundary Desk separates one-call answers, UI capabilities, provider safety acknowledgements, and host authority.

The complete practice data is in Approval Desk’s cases, Dispatch Desk’s cases, and Boundary Desk’s cases. These are inert JSON records, not OMP configuration, executable extensions, or shell scripts. seed_note and seed_slot are fictional recording tools used by the supplied private verifier; this workbook does not install them. An action string named publish does not contact a publishing service. Shell-shaped strings are objects of classification only: do not execute them or submit them to OMP.

Use the paper route

For each worked case, cover the answer, predict the decision, inspect the fictional inputs, and compare your explanation with the recorded outcome. Keep three labels separate:

  • Source-backed: follows the supplied implementation snapshot of 30 August 2026.
  • Recorded: describes a completed check in a supplied report, under that report’s conditions.
  • Paper checkpoint: a falsifiable question for the reader; answering it is not a new runtime test.

The website’s example controls select authored reading milestones. They do not evaluate your settings, resolve a real permission policy, answer an OMP dialog, or run a fixture. The default route requires only the text and fictional data. No credentials, provider prompts, personal settings changes, SSH connection, privileged broker, or new simulator are needed.

Tool permissions and approvals · Source chapter: permissions/orientation. Original evidence remains scoped to its recorded snapshot.

Read this chapter as Markdown

Your lesson ticks

A self-reported reading checklist, not proof of real OMP behavior. Only these ticks are saved in this browser. Reading a milestone does not resume, fork, reset or export a session.

Chapters I have worked through
Start here 1
Sessions, resets, and reviewable history 19
Memory and reusable knowledge 14
Tangent work and live control 17
Tool permissions and approvals 15
Extensions inside those boundaries 23
Connections and next steps 8
0 of 97 checked

Checklist saving needs JavaScript and available browser storage.