Submilli’s permissions model works from the inside out. Submilli has packages, like every other language. The package defines the permission vocabulary for a capability. For example, a refund capability comes with a payload that includes a customer ID and an amount. The interpreter checks, in real time, if that capability was granted to the agent, and denies or allows accordingly. That allows writing rules like “Allow a refund up to $500, only for customer 123”.
Submilli compiles TypeScript to WebAssembly, comes with ECMA-262 and a standard library with a restricted API to the outside world, which is also governed by the above permission model.