request_apply_commit was removed with the non-PR config flow; the
approvals tool group is exactly request_init_config and
request_update_meta_inputs (hive-sh4re/src/permissions.rs). The system
prompt every agent is rendered from still named it three times, so an
agent could read the prompt, call the tool it describes, and get an
unknown-tool failure with nothing pointing at why.
Also fixed the approval-boundary paragraph's description of the config-
change flow itself, not just the tool name: creating an agent is
request_init_config then the operator's own Spawn approval from the
dashboard; changing an agent's config is a forge PR on
agent-configs/<name> that queues a MergeConfigPr approval on open/update
-- no MCP tool call in that path at all. docs/tools/lifecycle.md already
described this correctly; only the prompt was stale.
fixes#4226