Agent-ready, not agent-trusting
The proposition that agent-ready must not mean agent-trusting is strongly supported. An agent runtime should hold short-lived, narrowly-scoped, audience- and purpose-bound, preferably sender-constrained credentials — never a single broad ambient credential. The model knowing how to call a tool says nothing about whether, in whose name, or under what constraints. See identity and authorisation.