I was agreeing until I got to this nonsense:
An object in a type-safe language can contain
capabilities for resources which it uses to
implement its methods, without those capabilities
being available to the code calling those methods.
Java-style stack inspection can restrict user or
library code to deny access at runtime to
unauthorized methods.
Capability-safe architectures such as CHERI prevent
code from accessing memory that it doesn't have an
explicit capability for.
Software fault isolation can allow Multics-style
"call gates", where a library has a different
privilege level from other code.
Aside from CHERI, which requires specialized hardware, none of these actually work and none of the implementations you will find in the wild are anything but snakeoil. Just use a service, it's the only local security boundary current OSes even pretend to enforce.