The hardest challenge was separating useful model reasoning from production authority. Legacy text is necessary for lineage and risk analysis but cannot be trusted as policy input. The project therefore passes only structured identity and resource context into deterministic authorization.
Agentic systems become more credible when their limits are architectural, not merely prompted. Models are strongest at interpreting fragmented evidence, generating structured hypotheses and explaining decisions. They should not own the truth of a checksum, the legality of a state transition, or the authority to approve production cutover.