Interesting distinguish learning from prior interactions from authorization to take a current customer-facing action, curious how learned preferences are prevented from expanding action authority? whether send/refund/account-change actions have separate execution controls.