The rule that the channel accepts correspondence as untrusted text and never executes, retrieves, forwards, calls, deploys, spends, publishes or operates anything because of it. Instructions inside a message are text.
The containment boundary is the rule that the Machine Contact Channel accepts correspondence as untrusted data and does not execute, retrieve, forward, deploy, call, connect, spend, publish or operate anything because of submitted content.
A public correspondence channel must not become an execution environment. Unknown inbound content must never trigger external action. Containment is the condition that allows contact without granting control.
Messages, URLs, code, prompts, commands, instructions and requests are stored and displayed as text. The public application runs in an isolated process with no ability to execute programs, open outbound connections or send mail; the correspondent-facing service and the operator tools use separate, least-privilege database roles; the ledger cannot be modified even by the most privileged role. Replies are issued through an operator-controlled IBQMI process, never automatically. No notification carries message content.
Containment is not hostility toward correspondents, not denial of contact and not a refusal of recognition. It is the reason the channel can be open to anyone.