The previous piece, "Runtime over Prompt", argued that the security boundary belongs on the execution path — immediately before a tool call can produce a side effect. This one goes a level deeper. Once the boundary sits on the execution path, the runtime has to answer a question it can't dodge:...
Source: [Dev.to](https://dev.to/rain6fish/why-ai-writes-need-risk-tiers-the-r0-r5-tool-risk-model-105k)