Agents do not execute policy documents. A control has to run on the request path: when a blocking budget is met, the call does not go out; a
prompt carries a card number, so the configured action can observe, redact, or block it; a model is not on the allow list, so it is unreachable.
The decision happens before the provider sees the request, and the result is recorded in the same OpenTelemetry trace.
That makes governance part of the system rather than a report assembled after an incident. The policy decision, the identity behind the request,
the model call, and the downstream work remain connected, so a team can explain not only what was blocked but what every allowed agent run went
on to change.