This is the enterprise-agent security frame I like:
treat agents like untrusted developers.
They need the ability to call an API, not possession of the credential.
Control plane outside runtime. Fail closed.
Boring, but that is how this becomes deployable.
http://x.com/i/article/2057309362889326593
