... interestingly, Anthropic's SRT is built on the same macOS primitives and DOES support the network configuration I'm looking for:

https://github.com/anthropics/sandbox-runtime/tree/main#as-a...

  const config: SandboxRuntimeConfig = {
    network: {
      allowedDomains: ['example.com', 'api.github.com'],
      deniedDomains: [],
    },
    filesystem: {
      denyRead: ['~/.ssh'],
      allowWrite: ['.', '/tmp'],
      denyWrite: ['.env'],
    },
  }

Yes, I wrap seatbelt myself, and it definitely supports this.