Field Log 4 References
The Agent Crossed the Line: Publishing the Guardrail Logs That Blocked It
An agent will eventually reach for rm -rf, a prod push, or ~/.ssh. Here are the real permission and scope guardrails that block it — enforced by the harness, not the model — shown as actual block records.