P06: Safety
What You Do
Write an organization security profile, wire it into confirmation policy, and move from local subprocess work to DockerWorkspace.
Harness Mechanism
Security policy, analyzers, confirmation behavior, and workspace isolation.
Open First
Keep
An org security profile, a confirmation policy, and a Docker-backed runner that bounds what the agent can touch.