Review and Confirmation
Keep consequential changes visible and explicitly confirmed.
Before execution, the user should see what changes, where it changes, which permissions are used, what side effects may occur, who will execute it, and how the result can be recovered.
Confirmation is bound to the current principal and prepared draft. It is not a permanent grant and cannot be reused after expiry or a material context change.
How is this guide?