It was untracked but not ignored, so a single `git add -A` would have
committed one operator's local permission allowlist — including which vault
secrets they may decrypt — as shared repo config. `.claude/settings.json`
stays tracked as the reviewed team config.
The previous commit swept in .claude/worktrees/city-resolver and
.claude/worktrees/thermograph-mentions as embedded git repositories. Those are
other Claude sessions' live checkouts and have no business in this tree.
Ignoring the directory so `git add -A` cannot do it again — the repo already
has a documented history of parallel sessions colliding through shared
checkouts, and this is the same hazard wearing a different hat.
Claude-Session: https://claude.ai/code/session_0182KTMrsTHJc3TcewCatJFY