Agents that can transact and coordinate with other software is where it gets interesting, and also where identity and permissions get messy fast. How are you handling scoped access when one agent acts on a user's behalf inside another service? Short-lived tokens, per-action approval, something else?