Use when the user wants to: harden service limits/protection ("so it cannot be farmed", "add rate limit"), add metrics/logs/alerts, figure out why metrics lie, fix "database is locked", configure log files without conflicts, conduct a security audit (secrets, admin privileges, mass mailings). Covers: env-limits with safe defaults, metrics (newly_credited, upsert, snapshot), three-tier logging and audit logs, SQLite busy_timeout+WAL, rate-limit at the edge with monotonic, non-blocking event loop, secrets and token fingerprinting. Do not use for incident debugging (debug-incident-protocol) and refactoring (agent-refactor-safety).