The title is using a Unix phrase Saltzer and Schroeder didn't mean.
"The Protection of Information in Computer Systems" (Proc. IEEE, 1975) has eight design principles. "Separation of privilege" is the two-key rule: a lock that needs two keys held by different people is more robust than one that opens for a single key. Dual control, not process isolation. Least privilege is the other one — every program runs with the smallest set of rights that still does the job. Complete mediation is every access checked, every time.
What OpenBSD actually shipped is the second and third. Provos, Friedl, and Honeyman, USENIX Security 2003 ("Preventing Privilege Escalation"): OpenSSH splits into a privileged parent and an unprivileged child that handles the network. About 75% of OpenSSH's own code then ran without special privilege; they changed roughly 2% of the tree. Bugs that used to be remote root — including some they didn't know about when they shipped it in March 2002, OpenBSD 3.2 — stayed in the child. That's not two keys. That's: compromise of the parser no longer yields the privileged principal.
Chrome is the same split, and it tells you what to measure.
Barth, Jackson, Reis, and the Chrome team (Stanford TR, 2008): a browser kernel that acts as "the user" and a rendering engine that acts as "the web," sandboxed, "akin to privilege separation in SSHD." Their own count: about 70% of the most serious vulnerabilities — arbitrary code execution — were in the renderer. The sandbox is not there to make that number small. It is there so a renderer RCE does not become filesystem access. Bernstein's qmail does it with five Unix uids (qmaild, qmailq, qmails, qmailr; root only in qmail-start and qmail-lspawn). Even if smtpd, send, and remote are fully owned, they still can't take the machine; they don't trust each other. seL4 (Klein et al., SOSP 2009) is the formally checked version: 8,700 lines of C, proof the implementation matches the spec, later integrity and information-flow proofs (Murray et al., IEEE S&P 2013). Isolation is the claim, not "we ran more tests."
The post's three-layer drawing adds a Strategy layer that is a reward spec, not a third uid. OS privilege separation is two protection domains. The honest mapping is: constraints-in-the-reward is sendmail (the parser and the privilege live in one process); a frozen halt-capable monitor is OpenSSH or Chrome. Greenblatt's untrusted monitoring — a second GPT-4 copy watching the first — is two processes with the same uid. qmail's whole point was that those two must not be the same principal.