Put rules at the capability boundary: Use policy engines, identity systems, and tool permissions to determine what the agent ...