## Orientation

A tool call can stop without offering a dialog\.&#32;Another call can run without asking\,&#32;even in a mode named&#32;`always-ask`\.&#32;A call displayed as&#32;`write`&#32;can actually dispatch a different tool\,&#32;with a different tier and policy key\.&#32;None of these observations is explained adequately by saying that permissions are simply on or off\.

This part teaches an operator’s method\:&#32;**identify the exact operation\,&#32;follow the policy that applies to that operation\,&#32;and distinguish permission to proceed from evidence of an effect\.**&#32;You will read enough TypeScript to understand the decision\,&#32;but you do not need to build an extension or make a provider request\.

The practice setting is the fictional&#32;**Cedar Seed Library**\.&#32;Its three desks are a sequence of reading exercises\:

- **Approval Desk**&#32;classifies declarations\,&#32;modes\,&#32;policies\,&#32;and ordered shell rules\.
- **Dispatch Desk**&#32;follows an operation through a&#32;`write`&#32;envelope into an argument\-sensitive device tool\.
- **Boundary Desk**&#32;separates one\-call answers\,&#32;UI capabilities\,&#32;provider safety acknowledgements\,&#32;and host authority\.

The complete practice data is in&#32;[Approval Desk’s cases](<https://present-sketch-tp94.here.now/examples/approval-desk/cases.json>)\,&#32;[Dispatch Desk’s cases](<https://present-sketch-tp94.here.now/examples/dispatch-desk/cases.json>)\,&#32;and&#32;[Boundary Desk’s cases](<https://present-sketch-tp94.here.now/examples/boundary-desk/cases.json>)\.&#32;These are inert JSON records\,&#32;not OMP configuration\,&#32;executable extensions\,&#32;or shell scripts\.&#32;`seed_note`&#32;and&#32;`seed_slot`&#32;are fictional recording tools used by the supplied private verifier\;&#32;this workbook does not install them\.&#32;An action string named&#32;`publish`&#32;does not contact a publishing service\.&#32;Shell\-shaped strings are objects of classification only\:&#32;**do not execute them or submit them to OMP\.**

### Use the paper route

For each worked case\,&#32;cover the answer\,&#32;predict the decision\,&#32;inspect the fictional inputs\,&#32;and compare your explanation with the recorded outcome\.&#32;Keep three labels separate\:

- **Source\-backed\:**&#32;follows the supplied implementation snapshot of 30 August 2026\.
- **Recorded\:**&#32;describes a completed check in a supplied report\,&#32;under that report’s conditions\.
- **Paper checkpoint\:**&#32;a falsifiable question for the reader\;&#32;answering it is not a new runtime test\.

The website’s example controls select authored reading milestones\.&#32;They do not evaluate your settings\,&#32;resolve a real permission policy\,&#32;answer an OMP dialog\,&#32;or run a fixture\.&#32;The default route requires only the text and fictional data\.&#32;No credentials\,&#32;provider prompts\,&#32;personal settings changes\,&#32;SSH connection\,&#32;privileged broker\,&#32;or new simulator are needed\.
