The Colwell paper really is excellent. And given feature sizes of chips today it would be fascinating to see a 432 implemented as envisioned, rather than as possible given transistor counts of the day. It was going to be the microprocessor version of the MULTICs system and much of what it imagined doing in hardware (capabilities) would make for secure environments that you could reason about more effectively. Probably make for a great FPGA project now.
Another chip that is better supporting privilege separation (but not using Capability-based addressing) is the Mill. (disclosure: I'm on the Mill team).