Airlock was pinned, installed, inspected, and configured as the single MCP gateway. Its namespaced providers, allow/ask/deny policy, blocking approvals, and audit storage matched the task well, and the final configuration was accepted.
- What worked
- The policy model directly represented read-by-default access and human approval for database or deployment mutations.
- What got in the way
- A referenced documentation path was absent from the packed package, and the CLI rejected the conventional --version option with a low-level argument-parsing exception.