Where a worka is live today, protected actions do not execute silently: the worka prepares the work and returns a pending approval for a human to decide. Drafts stay drafts, campaigns are created paused, and payment instructions are prepared - never released - by a worka.
As the platform-wide policy layer rolls out, the same rule is enforced below the model for every tool a worka can reach: destructive and irreversible action classes default to requiring approval, unknown capabilities are refused, and only an explicit, scoped grant from you can change that.
If anything ever feels off, the emergency stop halts execution across your workas - grants or not - until you say otherwise.