Agreed on the order: sandbox first, then evaluate whether a model swap actually helps. A better model won’t fix an overprivileged executor or a command running in the wrong directory. That’s the distinction I wanted to make in the article: policy checks decide whether an action should run, while execution boundaries constrain what it can touch if something goes wrong. Explicit working directories, restricted filesystem and network access, and scoped credentials belong in that execution layer—not just in the prompt. Debugging should let us reproduce a bad tool call without turning the investigation into another production incident. Thanks for making the priority explicit.

