Make landing the last step of the work, not a question. master
Both entry points already said to land completed work without waiting for routine permission, but neither said the failure mode out loud, so a session could satisfy the letter of the rule and still stall on "committed on a branch, want me to land it?" — which is the permission request restated. Names the two mechanical facts that turn a landing into an ask when they are not known in advance: task.sh finish requires a heartbeat run owning the worktree plus AGENT_ID, and a shared checkout dirtied by a concurrent session cannot fast-forward. Pushing worktree-<task>:main straight from the task worktree lands without touching that work, and the site scripts run from the worktree because they resolve their root from their own path. Records that site-smoke normally needs SITE_SMOKE_ATTEMPTS=12. Defense: process doorway only. No simulation rule, save format, or player surface changes, so no law or spec page owns this text; AGENT.md's Landing section and the CLAUDE.md guardrail list are its owners.