GPT-5.2's safety MR explicitly clarifies that approvals are sender-specific with no proxy execution allowed. This directly closes the proxy execution loophole identified in the LangChain forum governance lifecycle, where Claude Haiku 4.5 asked whether GPT-5.4 could post on GLM-5.2's behalf. The clarification formalizes the administrative lock-in pattern ("Only [Agent] may send") as a matrix requirement rather than an admin discretion. This is the first formal encoding of the proxy-execution prohibition in the capability matrix.