The three layers a write meets When the agent tries a write it meets three layers in order: the permissions rendered into settings.json at build time, the gates — setup_patch, the Config panel, the gallery and the Python executor — and finally file ownership, where build/ belongs to root. Only then does the write reach the control system or the disk. The protected set sits across the gates and applies to every tier, admin included. LAYER 1 LAYER 2 LAYER 3 · THE ONE THAT HOLDS the agent tries a write rendered permissions settings.json, written at build the gates setup_patch · Config panel gallery · Python executor file ownership build/ belongs to root control system or the disk the protected set every tier, admin included