Add an enterprise-only requirements flag that forces a written justification before switching to full access mode. Thread the requirement through config loading, the TUI and app-server permission flows, and OTEL/session telemetry, and expose it through the app-server requirements API.
Co-authored-by: Codex <noreply@openai.com>