Executor human-in-the-loop
State-changing commands the capability-scoped executor refused to auto-run. Each is shown exactly as it would execute — the hardened argv, the signed-scope reference it was authorized under, and its danger class. Approving runs it (still through the egress-locked sandbox, with the scope re-checked at execution time); rejecting discards it. Every decision is audited.
No executor is wired to this deployment. Parked commands appear here once an operator drives the capability-scoped executor through this dashboard.
Deciding an executor command requires the reviewer role.