Tool permissions and approvals: next steps
You can now explain a permission outcome without treating every refusal as a request for a wider grant. You can distinguish an absent tool, an effective deny, a declined call, unavailable UI, revised input, and a later host error. You can also explain why no prompt is not proof of either safety or a broken gate.
Carry the operator contract into design
The next part asks how a capability should expose those boundaries. Host approval is only one layer. Seed Desk’s branch-persisted authority, Review Desk’s one-action revision grant, and Field Notes’ factory-local selection have different lifetimes. None should be silently replaced by a generic approval answer.
Continue to Extensions inside those boundaries. Read its complete examples as designs whose domain checks, host wiring, delivery, and verification must agree—not as a way to bypass an operator’s policy. The shared connection Permission belongs to an operation, a revision, and a lifetime compares the layers without merging their grants.
Tool permissions and approvals · Unified editorial chapter; connects the recorded source material without rerunning it.