Real-time policy enforcement, kill switches, and human approval — before an agent's action executes, not after.