I like the idea of scoping permissions explicitly because it moves the security boundary away from the model's judgment. One thing I'd add is that the permission model itself should be versioned and inspectable. Once an agent can call tools repeatedly across a workflow, debugging “why was this allowed?” becomes just as important as deciding whether the capability should exist.