Your rules stay above the model.
Evaluates proposed actions against an integrity-protected local allow, deny or require-approval policy scoped by toolkit, capability, host or path.
The AI never receives direct operating-system privileges. Tool calls are resolved against the exact Idovio binding and pass through permissions and sandboxing.
The same execution policy applies regardless of which AI proposes the action.