## Tangent work and live control\:&#32;next steps

The useful endpoint is not merely “the tan stopped\.” It is a report that identifies the target\,&#32;distinguishes job and agent state\,&#32;locates the available output\,&#32;and accounts for already\-written files or separately supervised processes\.&#32;Likewise\,&#32;“the message was delivered” does not establish that the requested correction was followed\.&#32;Completion\,&#32;delivery\,&#32;returned output\,&#32;and effects are different facts\.

The next question is why a particular operation was permitted at all\.&#32;A tangent can inherit a per\-tool policy record while its initial settings helper defaults the approval mode to yolo\.&#32;Its narrow assignment is not an OS boundary\,&#32;and its initial headless construction is not Main’s interactive approval experience copied intact\.

Continue to&#32;[Tool permissions and approvals](<https://present-sketch-tp94.here.now/chapters/unified-permissions>)\.&#32;Follow the exact call through tier classification\,&#32;effective policy\,&#32;device dispatch\,&#32;one\-call answers\,&#32;and host UI availability before treating a refusal as something to repair or a missing prompt as proof of safety\.

Extensions can then make these distinctions easier to operate\:&#32;explicit tools can expose identity and revisions\,&#32;lifecycle handlers can retire stale authority\,&#32;and owner\-addressed delivery can keep a result with its originating conversation\.&#32;They do not remove the underlying boundaries or automatically install themselves in every child runtime\.

After permissions\,&#32;continue to&#32;[Extensions inside those boundaries](<https://present-sketch-tp94.here.now/chapters/unified-extensions>)\.&#32;The design question remains how to make a capability’s actual scope visible to both a human and an agent\.
