An MCP server that enforces runtime governance on AI agent actions — file access, command execution, delegation chains, and permission escalation.