Great breakdown of the NHI problem space, especially the borrowed trust angle. Machine keys dont have contextual expiry, they rarely have two-factor, and once one leaks theres no clean way to trace which agent used it for which downstream call. Most orgs invest heavily in secret rotation and vault hygiene but the delegation tracing gap - who authorized what and from which workflow - is where incidents actually happen. Managed PKI and short-lived certs seal the secret side but leave that whole audit layer untouched. Thats the part that makes NHI management feel like a blind spot despite all the investment in vault tooling. At CAI weve been looking at binding agent identity to verifiable on-chain attestations so every delegation leaves a verifiable trail. Curious if youve explored that direction or if your approach stays in the vault layer.