ReadonlyallowReadonlyconfirmsOperation rows whose fire is gated behind the operator's confirm setting, keyed by the
operation row's own path (ConfirmGate, 2026-08-22-osc-surface.md). Absent from a desk
that publishes no confirm map, which reads as "nothing here needs asking" — the honest
answer for a console that gates nothing. A remote surface with no dialog of its own reads
this to find the SAME preview and the SAME sign-off the web UI's useApplyWarning reads,
rather than growing a second policy.
ReadonlydefaultsReadonlydemandThe rows the desk declares PUMP-FED — telemetry a subscriber is sent only for the entries in its demand (demand gate §3d: which rows are pump-fed is CONTRACT, never a hand list in a client). A remote surface needs it for two different reasons and both are the same reason: it must DECLARE such a row to receive it at all, and it must not treat one as board state if it ever does. Absent from a desk that publishes no demand map, which reads as "no row is pump-fed" — the honest answer for a console that gates nothing.
ReadonlyresourcesReadonlytravels
The whole desk's declaration, as
OPTIONS <base>/answers it.resourcesis the address space's alphabet: every template the console will answer, so a client resolves an incoming address against them rather than against a list it was built with.