A 311 resident-services team is loosening permissions so routine sessions stop prompting for read-only git inspection. A developer proposes adding Bash to the allow list. The architect objects and wants the narrowest rule that still removes the prompts for git status. What should be added to the allow list?
Select an answer to reveal the explanation.
Short Explanation
Permission rules take a specifier in parentheses, so you can approve one command instead of the whole shell. Bash(git status:*) opens exactly one door; bare Bash is a master key that also fits rm and curl.
Full Explanation
Least privilege is the habit of granting the smallest capability that removes the observed friction, rather than the largest grant that certainly covers it. The 311 team's actual friction is a prompt on one read-only inspection command, so the grant should be shaped to that command and nothing wider.
Permission rules accept a tool name with an optional specifier, and for Bash that specifier is a command pattern. Writing the rule as Bash(git status:*) pre-approves that command with any arguments, which is precisely the prompt-free experience the team asked for, while every other shell invocation on the resident-services repository continues through the normal permission path.
Allowing bare Bash pre-approves every shell command the model can construct, and the accompanying CLAUDE.md note is guidance rather than enforcement so it cannot constrain what the grant actually permits; Bash() is equally unrestricted, and the reassurance about the working directory is misleading because a shell command is not confined to the repository; and Bash(git:) is narrower than the first two yet still covers every git subcommand, including history-rewriting and push operations, so it is not the narrowest rule the syntax supports.
Exam caveat: command-pattern matching is textual, so a rule anchored to one spelling does not cover equivalent invocations written differently, and an over-narrow rule simply restores the prompts it was meant to remove. Operational check: after adding the rule, run the exact inspection command and confirm no prompt, then run a different git subcommand and confirm it still prompts.