The article distinguishes between instructional guidance (like CLAUDE.md files) and enforced security boundaries for coding agents. It argues that telling an AI agent what to do is fundamentally different from technically controlling what it can do, and recommends applying least-privilege principles to agent permissions the way you would for service accounts.