What
Implement the planned garrison-execpolicy (garrison-agent-design.md §1.1): prefix rules in TOML plus command canonicalization, so bash -lc "git status" is matched on the argv it actually runs and policy cannot be laundered through a shell wrapper. Decisions map allow → auto-approve, prompt → IDE round-trip, forbidden → deny with reason fed back to the model, with justification surfaced in the audit entry. Rules ship in the control-plane bundle and are self-tested against their examples at publish like the existing command rules.
What
Implement the planned
garrison-execpolicy(garrison-agent-design.md §1.1): prefix rules in TOML plus command canonicalization, sobash -lc "git status"is matched on the argv it actually runs and policy cannot be laundered through a shell wrapper. Decisions map allow → auto-approve, prompt → IDE round-trip, forbidden → deny with reason fed back to the model, withjustificationsurfaced in the audit entry. Rules ship in the control-plane bundle and are self-tested against their examples at publish like the existing command rules.