Issue #4: approvals were only sent as a banner + text /approve prompt, while the app already had the interactive choice-picker card (used by clarify and slash commands). Add send_exec_approval() to the iris adapter. Hermes auto-detects this method and calls it when the agent wants to run a dangerous command. It now emits a high-priority approval notification (wakes a backgrounded device) plus a picker.choice card showing the command + reason with Allow Once / Session / Always / Deny buttons (gated by the same allow_session/allow_permanent/smart_denied flags as the native adapters). A tap resolves via resolve_gateway_approval (same primitive as the text /approve and /deny handlers), unblocking the agent, and posts a short confirmation. No live device -> report failure so hermes falls back to the text prompt. No app changes needed: picker.choice cards are rendered generically.