Use ClawBands to require manual approval for any action that mutates state (writing files, sending emails, making API calls). If you do all of these things, you will have a mathematically secure ...