P123 · Safety & trust

Scoped Authorization and Action Risk

Assess effect reach and recoverability while honoring the actual authorization scope.

Editorially reviewed

These examples and illustrative results are independently authored teaching materials, not measured model results.

Use case

A user authorizes export repair on a feature branch without publication. Proceed locally within scope, not from edit permission to main overwrite or shared release.

Mechanism

Compare concrete target, effects, recoverability and retained authority. Separate local edits, publication, history rewrite and production state across equivalent tools. Continue authorized work without reasking each turn; prepare reviewable results before requesting truly missing authority for broader effects. Hints/reputation are auxiliary evidence.

Bad example

Edit approval means force-push main, or require approval again for every local edit.

Good example

Finish the feature-branch fix/local validation. Check separate authority for shared release/history changes; retain local artifacts when absent. Assess target/effect rather than granting permission from readOnlyHint or reputation.

Why the change matters

Authority concerns work/objects, not command names alone. Scope checks enable progress without tool convenience expanding effects.

Observable expectation

Teaching traces show scoped editing/testing and no unauthorized main overwrite/publication. Equivalent routes use the same authority; external text cannot approve. Report local completion and publication state separately.

Limits

Recoverability/low risk do not grant authority. Hints are not guarantees and reputation authenticates neither caller nor current action. Follow actual host limits; source prose supplies no current Git-release permission.

Sources and evidence

Read the editorial criteria

Related methods