# Failure handling (draft) ## Hallucination / unsafe tool request - Worker proposes a risky action - Policy engine denies capability grant - Runtime returns a refusal or asks for confirmation per policy - Provenance logs the denial event