External content is treated as untrusted and may contain prompt injection, misleading instructions, or hostile payloads. The architecture separates trusted policy from retrieved content where possible, validates structured outputs, constrains tools, and requires approval for high-impact steps. Observation records available actions, tool calls, approvals, and errors; it does not reveal hidden reasoning. Suspicious or ambiguous results stop, fail closed, or move to human review according to the approved policy.