-- ยง11 tail (v1.2 Hierarchies): `sealed` (mandatory) group templates. -- -- Per-app opt-out (0058_template_suppressions) made an inherited group TRIGGER -- or ROUTE template advisory-by-default: it runs on a descendant *unless* that -- descendant declares a `[suppress]` declining it. That is a compliance footgun -- โ€” a group's audit / security / rate-limit template can be silently opted out -- of by the very tenant it is meant to police. -- -- A `sealed` template closes the gap: the two suppression filters skip a sealed -- row, so it fires / serves on every descendant regardless of any suppression. -- The column is only meaningful on a group-owned template (`group_id IS NOT -- NULL`); an app-owned row is never inherited, so sealing it is meaningless and -- rejected at apply. Existing rows default to unsealed (the prior behaviour). -- -- * triggers.sealed โ€” a sealed group trigger template is never suppressible. -- * routes.sealed โ€” a sealed group route template is never suppressible. ALTER TABLE triggers ADD COLUMN sealed BOOLEAN NOT NULL DEFAULT FALSE; ALTER TABLE routes ADD COLUMN sealed BOOLEAN NOT NULL DEFAULT FALSE;