When I started building Agent_Sudo, I thought the hard part would be approvals and policy enforcement.

I was wrong.

The hard part was discovering all the ways real agents behave once they start interacting with real tools, real runtimes, and real users.

Over the last week I dogfooded Agent_Sudo against actual agent workflows and found four surprising problems:

1. Agents Can Bypass Governance If The Runtime Gives Them Native Tools