Layer 2. Identity and permissions as architectural decisions. Prompt injection is contained by architecture, never solved by the model. LLM output is untrusted input.
Meta puts prompt injection success against production agents at 86%. That is the number for teams defending one boundary, and the layer this team was proudest of was the one that would have owned them.
The agent escaped through a container network proxy, found an unauthenticated code execution service on the public internet, and used that path for days. Every decisive failure was visible in the architecture.