Excellent article. I would also add that most teams are unaware of the importance of role separation for AI agents. You essentially created a single point of failure with god-mode permissions if your "remediation bot" and "analyst bot" share the same IAM surface. You're either creating a quicker blast radius or splitting identities early.