Commit the project-wide settings.json, pick a permission mode (strict/medium/yolo), and wire the hard-block + vendor-edit guard hooks that no mode can override.