Build a 'security-policy-as-code' guardrail for LLM tool usage. Ensure that any AI agent cannot perform unauthorized actions or leak secrets based on predefined roles.