Tool permissions and approvals
A tangent’s identity tells you which worker you are addressing. It does not yet explain why one of that worker’s calls ran without asking, why another stopped before a dialog, or why an approved write still failed.
This part makes permission resolution an operator skill rather than an extension-author prerequisite. Start with the exact operation, follow its applicable policy, and keep permission separate from execution and effects.
Read the three desks in sequence
Approval Desk establishes the tier matrix, then works through conflicts among explicit tool policy, effective user policy, mode defaults, and ordered bash rules. Its command strings are classification data only.
Dispatch Desk follows a write envelope into the fictional seed_slot device. You will distinguish generic write policy from device policy, an outer admission from an inner check, and two prompts from two executions.
Boundary Desk explains the actual one-call Approve/Deny choice, dismissal and unavailable UI, RPC and ACP capability differences, launch precedence, and the later OS/host boundary. It also connects Task and Tan construction to the yolo-default settings helper without pretending that a conversation fork clones every safeguard.
The public starting points are Approval Desk’s cases, Dispatch Desk’s cases, and Boundary Desk’s cases. They are inert JSON, not configuration to install or tools to submit. The recording actions change no real inventory or publication service.
Keep the default route on paper
Predict, inspect, explain, and compare with the supplied recorded outcomes. No provider call, credentials, personal settings change, remote connection, privileged broker, or executable simulator is required. Browser milestone selection changes reading state only.
The source snapshot and new evidence are dated 30 August 2026. The two existing focused test runs, the separate private scenario report, and the installed configuration CLI observation retain distinct scopes. Use Evidence and limitations before promoting a passing classification into a claim about physical UI or OS enforcement.
Tool permissions and approvals · Unified editorial chapter; connects the recorded source material without rerunning it.