Guides designing and implementing security guardrails, permission scoping, and execution
boundaries for autonomous AI agents and tool use. Covers principle of least privilege,
human-in-the-loop approvals, sandbox execution, argument validation, and blast-radius
containment. Use when exposing APIs, functions, bash commands, or databases to AI agents.
Do NOT use for UI button access control.