Four steps between an AI intention and a real-world effect
1. AI proposes
An agent wants to write a file, run a command, call an MCP tool, or open a network connection. Where a hook exists (Claude Code hooks, MCP transport, OpenClaw tool policy), the intent arrives structured; where none exists, the OS observation layer sees it.
2. Policy evaluates
The request is checked against the priority stack: System Security Boundary → User Hard Deny → User Explicit Policy → Task Capability → Adaptive Policy → Default Policy. Identity, lineage, behavior chain, resource sensitivity, and risk tier all feed the decision. AI plays no part in setting its own boundaries.
3. Enforcement happens natively
Decisions are enforced at the platform layer before the action takes effect — not logged-and-hoped-after. Fast Path keeps routine events cheap; Slow Path takes the time needed for ambiguous ones.
4. The system learns and can undo
Outcomes feed adaptive learning (through quarantine and confidence gates, never straight into rules). Recovery, undo, and policy replay make both agent mistakes and rule mistakes reversible.
Alerting without fatigue
Design targets: low false-positive rate, silent allow for routine work, escalation only for genuine risk, and an explanation for every block. Alert fatigue is a security bug, not a preference.