Managing agent identity and credentials under least privilege.
Agents need scoped identities whose authority matches the task. Secrets should be injected only at the action boundary, kept out of model context and logs, rotated, and separated from untrusted content.