Extract the full-access mechanism from PR #873 and make it the default for newly selected mutating sessions. Preserve owner row caps, readonly task authority, historical snapshots, exact retry custody, and explicit patch integration; schedule_subagent and delegate_start can only lower native access.
Keep scoped trust creation behind the existing gateway and retain explicit denials. Cover actor-first startup, ordinary folders, payload capture, role conversion, and shared Settings/onboarding flows without adding runtime functions or changing release versions.