This is the right frame, and the whole thing is already running. We built OutLayer around this exact question, and the answer turned out to be smaller than a policy engine: never let a model's output be an authorization in the first place.
Every signable action is a canonical
Ex-NEAR core | Building @out_layer | Data, facts, no hype. I research so you don't have to. Stake NEAR, 1% fee only ⬇
Joined January 2018




