This only works in the case of working with databases, also a lot of the times people are not careful with the permissions that are given to these agents and they oftentimes touch areas that they were not originally meant to touch. For example I use claude code from Frontend UI, to backend development to even marketing. The whole point of agents is that it is active rather than passive, making it read only essentially (imo) defeats the purpose of using an agent in the first place.
I'm not saying we shouldn't have built in precautions and permissions, this should be standard practices, but Doberman is a system built to handle the inevitable case when these precautions fail.