This is the right framing: the failure is that the output looks fine while the permission model is quietly wrong, which is the hardest kind of bug to catch because nothing actually errors. Modeling a request as an action with a purpose, allowed sources, and recipient constraints is what I have found actually scopes an agent, far more than handing it the whole workspace and hoping. In the four-layer model, which layer ends up owning the deny decision when purpose and identity disagree?