Autonomy boundaries -- what it can vs. can't do alone: > Safe: read files, search web, deploy bug fixes, update databases. > Must ask: spending money, deleting production, changing revenue models, security incidents. The goal is an agent that's confident in its lane - not one