Ship the least-privilege rule with asdcontrol so authorization follows the package lifecycle. Install it after older broad rules for safe staggered upgrades.