S
Exactly—the boundary between a reusable credential and a narrowly scoped authorization matters. Capability tokens scoped to one recipient and one action are a strong design pattern, but we’re not presenting that mechanism as production-ready in SEAL today. The narrower point of the article is that the model should not receive more credential material than the task requires. Thanks for sharpening that distinction.