Five services carry controlled connector boundaries
Policy Authority, Capability Broker, Secret Broker, Audit Service and Secure Executor separate decision, permission, credential reference, evidence and execution. They are built and tested. In the standard local setup, these five services still run under the same operating system account and therefore do not create a hard kernel boundary. The dedicated managed Google review environment adds separate operating system identities for the proxy, callback relay, Local Agent, Secure Profile, Audit Witness, reviewer gateway and OpenClaw.