## Recovery without widening permission

Nia can now replace “permissions are broken” with a specific account\:&#32;the target\,&#32;the applicable gate\,&#32;the observed refusal or admission\,&#32;and the effect count\.

Recovery begins with that account\.&#32;It does not begin by changing the whole session to yolo\.

### Start with the exact observed target and current scope

Before any later retry\,&#32;establish\:

1. The current persistent conversation and cwd when relevant—not merely a title from an old screenshot\.
2. The exact tool and call\,&#32;including any outer&#32;`write`&#32;envelope and inner device name\.
3. The original arguments\,&#32;supported replacements\,&#32;and actual destination or action under review\.
4. The tool declaration\,&#32;effective policy key\,&#32;mode\,&#32;and execute\-time autoApprove input\.
5. The host’s relevant UI capability and any independent provider safety requirement\.
6. Whether execution occurred\,&#32;which result belongs to which call\,&#32;and which effects remain uninspected\.

On the paper route\,&#32;use only the supplied fictional records\.&#32;If a fact is not in the record\,&#32;mark it unknown\.&#32;Do not create certainty by substituting your own settings or making a provider request\.

### Use the recovery matrix

| Observation | Boundary to investigate | Bounded recovery | What not to do |
| --- | ---: | --- | --- |
| Tool absent or&#32;`No such tool` | Enabled registry and actual direct\/mounted route | Confirm the exact known name and current availability\;&#32;use an already available appropriate surface or report the missing capability\. | Assume a user allow installs or discovers a tool\. |
| `blocked by tool policy` | The declaration’s effective deny\,&#32;including a selected bash deny | Read the exact reason and arguments\;&#32;preserve the refusal unless the responsible policy owner identifies an authorized correction\. | Expect yolo or a generic user allow to erase a tool deny\. |
| `blocked by user policy` | The effective normalized key\,&#32;including dispatcher fallback | Identify whether the key is the device or invoking tool\;&#32;compare the policy with the intended scope\. | Remove unrelated denies or treat the stock hint as authorization to change policy\. |
| `Tool call denied by user`&#32;after a selection | One\-call response\,&#32;dismissal\,&#32;or adapter returning no positive value | Retain the declined outcome\;&#32;reconsider the operation and input before any separately authorized retry\. | Treat it as a persisted deny\,&#32;or retry just to pressure another answer\. |
| Required approval but no UI | Runner UI installation and required operation | Stop\;&#32;identify whether the owning host has an appropriate supported approval surface\.&#32;Reading the refusal completes this workbook case\. | Widen the mode merely to make unattended execution continue\. |
| Prompt or result refers to revised input | Supported handler replacement and reclassification | Review the effective operation again\;&#32;correlate prompt\,&#32;tier\,&#32;and execution evidence\. | Approve by remembering the original input or assume every metadata field was rewritten\. |
| Domain stale\-revision refusal | The domain’s own object and revision contract | Inspect the current object and reconsider the action\. | Substitute a fresh token into an unchanged request without review\. |
| Malformed device JSON or schema error | Envelope decoding and inner validation | Compare the fictional payload with the actual schema\;&#32;repair only the intended input in a separately authorized real workflow\. | Loosen approval policy to repair invalid data\. |
| Pending provider safety checks | Provider metadata and explicit acknowledgement path | Keep the required decision separate from ordinary allow\/yolo behavior\;&#32;stop if it cannot be obtained appropriately\. | Treat autoApprove or xdev forwarding as acknowledgement\. |
| `EPERM`\,&#32;`EACCES`\,&#32;or&#32;`EROFS`&#32;after execution begins | Actual OS\/host primitive and resolved target | Preserve the error and relevant cause\;&#32;hand the exact authorized operation to the host’s normal diagnostic process outside this workbook\. | Assume another tool approval grants privilege or activate an elevated writer as practice\. |
| Extension handler block or timeout | Pre\-execution handler and its active\-work failure | Identify the failing handler and preserve the blocked call\;&#32;investigate compatibility or the supported domain path\. | Interpret a stalled gate as silent consent\. |
| A call ran without asking | The full resolution path | Check tier defaults\,&#32;tool allow\,&#32;selected rule\,&#32;policy key\,&#32;launch autoApprove\,&#32;child construction\,&#32;and supported forwarding\. | Infer either safety or a bypass from zero prompts alone\. |

The matrix deliberately distinguishes a policy denial from a declined call\.&#32;It also distinguishes a stale domain object from a handler\-revised tool input\:&#32;the generic approval wrapper is not itself a domain revision system\.

### Worked recovery\:&#32;an unexpected no\-prompt result

Read&#32;`dispatch-specific-allow`&#32;again\.&#32;The outer name is&#32;`write`\,&#32;generic write policy is deny\,&#32;and the fictional action is exec\-tier\.&#32;A superficial account says the gate ignored deny\.

A complete account says\:

- The target is&#32;`xd://seed_slot`&#32;and the outer declaration supplies that policy key\.
- The valid&#32;`seed_slot: allow`&#32;replaces the invoking&#32;`write`&#32;fallback\.
- The inner declaration does not deny this fictional action\;&#32;its user allow applies\.
- The report records zero prompts and one inert execution\,&#32;not a real publication\.

The immediate repair is the explanation\.&#32;Whether a real device\-specific allow is intended is a separate policy\-owner decision\.&#32;It is not permission to rewrite the reader’s configuration\.

Now compare&#32;`boundary-auto-approve-mode`\.&#32;Its no\-prompt result has another cause\:&#32;execute\-time autoApprove selects wrapper yolo despite configured always\-ask\.&#32;Do not diagnose it as a device\-policy issue\.

### Worked recovery\:&#32;an error result after outer admission

In&#32;`dispatch-inner-tool-deny`\,&#32;the outer transport reaches dispatch\.&#32;The inner policy then refuses\,&#32;and the dispatcher returns an error result\.&#32;There is one outer&#32;`tool_call`&#32;and no inert inner execution\.

A retry with the same denied action is not a missing\-dialog repair\.&#32;The operator must address the actual inner\-policy reason or leave the action blocked\.&#32;A transport return and an outer event are not evidence that the inner effect occurred\.

For a later real file error\,&#32;inspect the relevant effect before retrying\.&#32;Approval and cancellation are not rollback\,&#32;and a sequence of primitives can have partial results\.&#32;The prior Tan and Continuity chapters retain their own phase\-aware recovery boundaries\;&#32;this permission chapter does not replace them with a universal transaction guarantee\.

### Finish the exercise without resetting anything

Nothing must be cleared\,&#32;dropped\,&#32;or reset to complete these cases\.&#32;The fixtures are reading material\.&#32;Retain your written predictions and corrections if useful\.&#32;Do not use session resets\,&#32;memory deletion\,&#32;policy removal\,&#32;or personal\-profile changes as workbook cleanup\.

**Paper checkpoint\:**&#32;write a three\-sentence recovery note for&#32;`boundary-no-ui`\,&#32;naming the fictional target\,&#32;the actual stopped gate\,&#32;and the effect count\.&#32;**Worked answer\:**&#32;the exec\-tier&#32;`seed_note`&#32;call requires approval in always\-ask\.&#32;The supplied runner has no UI\,&#32;so the wrapper resolves false before execution\.&#32;The inert execution count is zero\;&#32;changing mode is not required to learn or explain the result\.

**Failure boundary\:**&#32;a useful diagnosis may end at an unavailable host capability or missing observation\.&#32;That is more accurate than manufacturing success through a wider grant\.

**Source trail\:**&#32;`packages/coding-agent/src/tools/approval.ts`&#32;—&#32;`denyError`\;&#32;`packages/coding-agent/src/extensibility/extensions/wrapper.ts`&#32;— refusal and selection paths\;&#32;`packages/coding-agent/src/tools/xdev.ts`&#32;— dispatch errors\;&#32;`packages/coding-agent/src/tools/file-write-fallback.ts`&#32;— primitive failure handling\.&#32;For separate domain recovery\,&#32;see&#32;[Review Desk](<https://present-sketch-tp94.here.now/chapters/extensions-review-desk-edit-and-decide-locally>)\;&#32;for session\-state boundaries\,&#32;see&#32;[Decision Desk resetting deliberately](<https://present-sketch-tp94.here.now/chapters/continuity-decision-desk-resetting-deliberately>)\.
