The point about “permission creep” is especially important. An agent may be properly scoped when it is first deployed, but once new tools, data sources, and workflows are added, the original accountability model can become outdated. I think periodic permission reviews should be treated almost like security reviews, especially for agents that can take irreversible actions.