I study security review guardrails and incident response through the decisions, constraints and evidence that shape delivery. Keep model inference, source context, validation, authorization, signing, execution, and audit records as separate observable stages.