Orientation
A tool call can stop without offering a dialog. Another call can run without asking, even in a mode named always-ask. A call displayed as write can actually dispatch a different tool, with a different tier and policy key. None of these observations is explained adequately by saying that permissions are simply on or off.
This part teaches an operator’s method: identify the exact operation, follow the policy that applies to that operation, and distinguish permission to proceed from evidence of an effect. You will read enough TypeScript to understand the decision, but you do not need to build an extension or make a provider request.
The practice setting is the fictional Cedar Seed Library. Its three desks are a sequence of reading exercises:
- Approval Desk classifies declarations, modes, policies, and ordered shell rules.
- Dispatch Desk follows an operation through a
writeenvelope into an argument-sensitive device tool. - Boundary Desk separates one-call answers, UI capabilities, provider safety acknowledgements, and host authority.
The complete practice data is in Approval Desk’s cases, Dispatch Desk’s cases, and Boundary Desk’s cases. These are inert JSON records, not OMP configuration, executable extensions, or shell scripts. seed_note and seed_slot are fictional recording tools used by the supplied private verifier; this workbook does not install them. An action string named publish does not contact a publishing service. Shell-shaped strings are objects of classification only: do not execute them or submit them to OMP.
Use the paper route
For each worked case, cover the answer, predict the decision, inspect the fictional inputs, and compare your explanation with the recorded outcome. Keep three labels separate:
- Source-backed: follows the supplied implementation snapshot of 30 August 2026.
- Recorded: describes a completed check in a supplied report, under that report’s conditions.
- Paper checkpoint: a falsifiable question for the reader; answering it is not a new runtime test.
The website’s example controls select authored reading milestones. They do not evaluate your settings, resolve a real permission policy, answer an OMP dialog, or run a fixture. The default route requires only the text and fictional data. No credentials, provider prompts, personal settings changes, SSH connection, privileged broker, or new simulator are needed.
Tool permissions and approvals · Source chapter: permissions/orientation. Original evidence remains scoped to its recorded snapshot.