97a06261b6
allowlist.json must be root-owned so POST /allowlist is the only write path; direct file edit bypasses audit log and danger veto. No cross- bridge sync — allowlists grow organically per server.