PMG grows two connected capabilities: (1) a generic policy evaluation engine (CEL over proto-defined contexts) enforced in the proxy lifecycle, and (2) proxy-enforced network control — the OS sandbox confines all outbound traffic to the PMG proxy (network_via_proxy_only), making the proxy the single enforcement point where per-host network policy finally becomes real (today, sandbox allow_outbound lists are documentation only: Seatbelt rejects non-localhost hosts, bubblewrap is binary).
PMG grows two connected capabilities: (1) a generic policy evaluation engine (CEL over proto-defined contexts) enforced in the proxy lifecycle, and (2) proxy-enforced network control — the OS sandbox confines all outbound traffic to the PMG proxy (network_via_proxy_only), making the proxy the single enforcement point where per-host network policy finally becomes real (today, sandbox allow_outbound lists are documentation only: Seatbelt rejects non-localhost hosts, bubblewrap is binary).