The actual wall everyone hits in production is domain-level state and credentials. When an agent holds valid API tokens and hallucinates a destructive action inside an authorized session, OS-level sandboxing won't save you.
For folks actually running agents in prod: are you gating every state-mutating API call with human approvals, or spinning up dynamic shadow environments to execute and verify side effects on mirrored state before committing?
AppD offers some SIEM. Splunk does much more than SIEM. Splunk Observability Cloud has nothing to do with Splunk Enterprise, it's a fully fledged AppD competitor.