Small models, short leashes
The scariest thing about an agent is not that it is stupid. It is that it is confident and has credentials. Capability and permission are separate axes, and almost every agent postmortem I have read confuses them.
A small model on a short leash fails safely. It cannot delete the wrong thing because it was never handed the ability to delete anything. When it is wrong — and it is wrong more often — the blast radius is a bad sentence rather than a bad migration.
The instinct is to reach for the largest available model and grant it broad access, because that maximises what it can do. But the thing that makes agents useful in practice is not the ceiling of their ability. It is the floor of their damage.
Running a 9B model locally forces this discipline. There is no budget for a model to wander. Every tool call has to earn its place, which turns out to be the constraint that makes the system legible.
The interesting question is not "how capable is the model". It is "what is the worst thing this configuration can do on its worst day", and that question has an answer you can actually write down.