Also, operating systems should let us set filesystem permissions per app/process/executable instead of just user accounts.
Similar to how macOS/iOS Sandboxing works but at a more lower and granular level
https://www.canyonroad.ai/ does some of this in a way tailored to agents.
personally I wish the OS would allow syscall filtering per user
[dead]
SELinux is basically this.