Canvas-changing commands plan when invoked without an apply authorization. Read
the plan and any expected-state guards before applying. Local-writing sync and
download commands are a different axis: their dry-run previews local changes and
they never accept the Canvas apply authorization.

After a write, trust classified readback and retained evidence rather than a
transport response alone. An accepted-unverified or indeterminate outcome is a
stop condition, not an invitation to retry blindly.

Missing danvas command coverage does not authorize direct Canvas API, browser
automation, or provider-specific fallback. Classify the proposed effect and ask
the operator before leaving the supported interface. A Canvas report request is
a mutation even when it does not change course content or grades.
