Allowed is not authorized is the right distinction, and the yes-or-no question that turned into a commit is the perfect origin story: the agent held the tool rights but had no authorization for that effect. The five authority questions are what an allowlist structurally cannot answer. When you check 'did the task authorize this effect', how do you represent the task's intent so tool_effects can be matched against it?