A maintainer-level agent can edit CI, but disabling a security scan before release may deserve `FREEZE`.
What This Shows
SMERC does not replace GitLab permissions. It adds the recovery question.
Existing platform policy can decide whether an agent has access to a tool. SMERC adds a narrower runtime check: should this exact action execute now, be throttled, frozen, denied, or escalated?
A production deployment that would normally ask for confirmation becomes `THROTTLE` with specific rollback and scope controls.
A project token may be valid while the requested permission expansion is too hard to contain or reverse.
An approval should not silently carry forward after deployment scope expands from one service to a group-wide rollout.
Boundary
Public-pattern benchmark only
This is synthetic GitLab-shaped metadata. It is not a GitLab integration, GitLab endorsement, GitLab telemetry, production deployment, customer validation, or proof of incident reduction.