Saving an agent or workflow that the server refuses with
sponsor_confirmation_required opens a dialog naming each tool, source or
prompt and who reaches it through the agent (its teams, API key and
widget, public link, webhook), then saves again with confirm_sponsor. A
save the caller may not sponsor shows why instead of the raw message.
The tool picker adds a remove-only row for each attached tool the editor
can't list, so the owner's private tools can be taken off the agent.