export interface GrantManager { addReadRoot(absPath: string, source: 'slash' | 'tool', sessionId?: string): void; addWriteRoot(absPath: string, source: 'slash' | 'tool', sessionId?: string): void; revokeRoot(absPath: string, source: 'slash' | 'tool', sessionId?: string): void; getGrants(): { resolveBase: string | undefined; readRoots: string[]; writeRoots: string[]; allowAll?: boolean; }; } export type GrantAuditAction = 'grant-read' | 'grant-write' | 'revoke'; export type GrantSource = 'slash' | 'tool'; export interface GrantSnapshot { resolveBase: string | undefined; readRoots: string[]; writeRoots: string[]; allowAll: boolean; } export interface PathGrantManagerHooks { getReadRoots(): string[] | undefined; getWriteRoots(): string[] | undefined; ensureInitialized?(): void; getProtectedRoot(): string | undefined; getDisplayResolveBase?(): string | undefined; getAllowAll(): boolean; getDefaultSessionId?(): string | undefined; } export declare class PathGrantManager { private readonly hooks; constructor(hooks: PathGrantManagerHooks); addReadRoot(absPath: string, source?: GrantSource, sessionId?: string): void; addWriteRoot(absPath: string, source?: GrantSource, sessionId?: string): void; revokeRoot(absPath: string, source?: GrantSource, sessionId?: string): void; getGrants(): GrantSnapshot; private appendAuditLog; }