A hook is not a security boundary
If the host is trusted, a governance contract can prove a deny. It cannot contain a host that never asks.
Deny has to mean deny
Framework callbacks observe. A governance contract has to stop the action, including when the guard crashes.
Two allowed actions can still be the breach
Per-tool permission is not an architecture. The control is which combinations you will not allow in one session.
MCP access is now an IdP problem
Enterprise-managed auth moves the privilege decision off the consent screen and onto identity policy. The blast radius moves with it.