* docs(agents): bind authorization to the change boundary
* docs(agents): require target identity confirmation
* docs(agents): classify operations by impact, not command form
* docs(agents): require reviewed previews for high-risk IaC
* docs(agents): verify production changes beyond exit codes
* docs(agents): sync new-script eval with current rules
* docs(agents): split global rules evals into smoke and extended
* docs(agents): refine change guardrails wording
- scope the guardrails to any environment, not only production
- preview high-risk changes with plan, diff, or dry-run
- trim redundant examples and simplify target identity confirmation
- confirm unclear targets with the user instead of stopping