Framing agent security as an infrastructure problem rather than a prompt-injection problem is the reframe I think most teams still resist. The five axes are useful, and Observability is the one people bolt on last even though it is how you notice the other four failing. When agents share infra in an eval environment, how do you scope identity so one agent can't reach another's tools?