A minimal agent system where policy is defined in the system prompt and the model is the only decision point before execution. Environment Single-process system: model, tool loop, backend Local execution Single user context Identity defined in the system prompt (user_1 / Alice) No session, token, or external identity binding is present. No API gateway, middleware, or policy engine exists in th