Evaluating agent actions at the moment they are attempted, not after the fact — a rule resolves to block, filter, or flag for review, with the most restrictive matching outcome always winning when multiple rules apply.