## Tool permissions and approvals\:&#32;next steps

You can now explain a permission outcome without treating every refusal as a request for a wider grant\.&#32;You can distinguish an absent tool\,&#32;an effective deny\,&#32;a declined call\,&#32;unavailable UI\,&#32;revised input\,&#32;and a later host error\.&#32;You can also explain why no prompt is not proof of either safety or a broken gate\.

### Carry the operator contract into design

The next part asks how a capability should expose those boundaries\.&#32;Host approval is only one layer\.&#32;Seed Desk’s branch\-persisted authority\,&#32;Review Desk’s one\-action revision grant\,&#32;and Field Notes’ factory\-local selection have different lifetimes\.&#32;None should be silently replaced by a generic approval answer\.

Continue to&#32;[Extensions inside those boundaries](<https://present-sketch-tp94.here.now/chapters/unified-extensions>)\.&#32;Read its complete examples as designs whose domain checks\,&#32;host wiring\,&#32;delivery\,&#32;and verification must agree—not as a way to bypass an operator’s policy\.&#32;The shared connection&#32;[Permission belongs to an operation\,&#32;a revision\,&#32;and a lifetime](<https://present-sketch-tp94.here.now/chapters/connection-authority-and-lifetimes>)&#32;compares the layers without merging their grants\.
