Human-authorized GCP write operations with named project plus explicit authorize write. Use when the human authorized the GCP change. Do not use for read-only inspection (gcp-read) or when authorization is missing.