Suppose your automated agent attempts to send an email when you have explicitly restricted its permissions to read-only access. Before that command ever reaches Gmail, Vic intercepts and halts the action entirely. No matter how many times the agent continues to ask, the system will automatically deny the prompt. Unauthorized actions are permanently shut down on every single occasion.
https://www.civic.com/news/agent-security-layer