We define what the agent may decide alone and what it must escalate before any implementation starts
That document is what your security team reads, and it is what stops scope creep when someone asks whether the agent could also issue refunds
Tools are typed and scoped, so the model cannot invent an endpoint it was never given








