Split from #1295 (closed as superseded).
The drift
The sheet row "ask before running" cycles prompt / allow / deny (internal/config/settings.go:513, the row at :1943). The approval card answers 1 allow once · 2 always, this command · 3 deny · esc later (internal/session/answers.go:218-222). /permissions says asks every time / every call / refused. The transcript says allowed / denied (internal/tui3/consent.go:440-445). The task settle row says ask / auto. The rules syntax says bash:prompt, read:allow, deny rm -rf *. The phrase "allow or deny", which people carry away from the card, exists nowhere in the repo: the paraphrase is itself evidence the surfaces do not share words. The row at rest reads "ask before running · prompt", a tautology whose other states read as negation and double negation.
Twelve rows also show one label in the panel and another in the registry: "tool exceptions" vs "tool approvals", "per day" vs "daily budget", "ask before spending" vs "per plan", and nine more (audit-notes/settings-inventory.md). A person told one name searches for the other.
The law (approved in #1295)
One word set everywhere, stated as consequences: ask every time / run without asking / never run. No row label contains one of its own answers. The card, /permissions and the transcript adopt the sheet's words; the registry and the panel show one label per row.
Evidence: the mismatch table with every file:line is section 9 of audit-notes/permission-wiring.md; the walkthrough is section 2 of #1295.
—
Co-Authored-By: codeaf agentfield-bot@users.noreply.github.com
Split from #1295 (closed as superseded).
The drift
The sheet row "ask before running" cycles prompt / allow / deny (internal/config/settings.go:513, the row at :1943). The approval card answers
1 allow once · 2 always, this command · 3 deny · esc later(internal/session/answers.go:218-222). /permissions says asks every time / every call / refused. The transcript says allowed / denied (internal/tui3/consent.go:440-445). The task settle row says ask / auto. The rules syntax saysbash:prompt,read:allow,deny rm -rf *. The phrase "allow or deny", which people carry away from the card, exists nowhere in the repo: the paraphrase is itself evidence the surfaces do not share words. The row at rest reads "ask before running · prompt", a tautology whose other states read as negation and double negation.Twelve rows also show one label in the panel and another in the registry: "tool exceptions" vs "tool approvals", "per day" vs "daily budget", "ask before spending" vs "per plan", and nine more (audit-notes/settings-inventory.md). A person told one name searches for the other.
The law (approved in #1295)
One word set everywhere, stated as consequences: ask every time / run without asking / never run. No row label contains one of its own answers. The card, /permissions and the transcript adopt the sheet's words; the registry and the panel show one label per row.
Evidence: the mismatch table with every file:line is section 9 of audit-notes/permission-wiring.md; the walkthrough is section 2 of #1295.
—
Co-Authored-By: codeaf agentfield-bot@users.noreply.github.com