A senior engineer opens a remote shell, meaning to check one container in staging. Instead, she has full root access across production nodes, S3 buckets, and even CI runners. One command later, chaos. This happens in real clouds today, anywhere teams rely on blunt session-based access. That’s why per-query