The problem :

core design principle (non-negotiable) : treat every agent action as delegated user access, never as the agent's own blanket access

Defining the Threat Model :

Solving the Threat Model :

Tackling the confused deputy attacks

Targeting the authorization flow

The 2 identity model

The difference from enterprise is that trust layer in enterprise needs to be a