Let servers request the filesystem or workspace boundaries that a client is willing to expose. Handle root changes carefully and keep server access inside approved locations.