The discussion of protecting the agent process is on page 7. swtch.com/~rsc/papers/...
What a cover!
In Plan 9 in ~2001, we introduced "private" processes that even a sysadmin couldn't access, debug, etc. I just learned Windows Vista added the same in 2007.
The difference? We did it to protect keys held by the security agent, while Windows did it to protect media content.
Priorities! ¯\_(ツ)_/¯