The UI below lives in a powerless data: chamber (no keys, no
storage, null origin). It stages files locally, then summons the origin's git over the probe line:
git.commit (Rung 1 — one confirm) and git.log/git.files (Rung 0 —
read, no prompt). The repo lives in this Elevated page; the chamber only names what it wants, and the
consent gate decides. A live demo of git-enough/probe-ops.mjs.