The “model proposes, policy disposes” framing is probably the most important architectural distinction here. Once tool calls cross into credentials, network access, or destructive side effects, the model should be treated as an untrusted decision source not the authorization layer.
One additional production concern is making the action broker the single observable choke point. At IT Path Solutions, I’d want every tool invocation to carry the agent identity, user/session context, policy decision, credential scope, and resource being touched. That turns an agent failure from “the model did something strange” into an auditable security event.
The kill-switch sequence is equally important. A control that exists only in documentation isn't really a control until the team has exercised identity revocation, session destruction, credential revocation, and spend freezing as one operational path.