Use to bound what an AI support agent may do to a customer's record — allowlists, irreversible actions, dry-run, audit trails, and blast-radius limits aligned with mutation-safety practice. Trigger for "what can the bot change on an account", "agent tool permissions", "AI agent safety bounds", "dry run before refund", "limit bot actions", or reviewing tool access before giving an agent write APIs.