A diligence report is not a code review. Here is what the review actually opens, in what order, and why the boring files decide the answer.
Why prompt-level guardrails are not enough, and how a two-plane architecture, least-privilege tools, and audit trails make agents safe to give real permissions.