docs(suppress): flag advisory-by-default trust model; test dangling-suppress warning (§11 tail review)
Two review findings. 1. Per-app opt-out changes the group-template guarantee from "runs on every descendant" to "runs unless the descendant declines" — a footgun for compliance hooks (an audit/security trigger a tenant can silently opt out of). There is no non-suppressible flag. Document this in design §4.5 + CLAUDE.md, and record the deferred mitigation: a `sealed`/`mandatory` group-template marker the trigger anti-join + route filter skip (cheap — both filters are centralized). 2. The dangling-suppress warning path had no coverage. The suppress journey now applies a `[suppress] triggers=["does-not-exist"]`, asserts the apply still succeeds and the report warns "no effect". Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in: