Sounds reasonable. I’d you, like me, need to protect yourself from sabotaging your own system you could even make NAS documents read only to force a manual step in before editing there.
For me the amount of items that should be there are zero following my own concept … But for some (especially shared sheets specifically) I’m too lazy.
Perhaps I should listen to my own advice here zzz


The issue is the whole UX behind it. I have yet to see someone review the 30th prompt of “grep” - there is no same default or middle ground.
For example whitelist read actions or harness side limitations to the project folder.
This is just lazy - again. “Users don’t use or very bad security feature so they just want us to disable it”.