> An agent cannot be its own security authority. It must run within a boundary defined by the developer or organization and enforced independently of the agent itself.
...so make it its own security principal, distinct from the human user?
> Without a managed execution boundary, the agent may decide that changing the server configuration is the fastest way to complete the task and potentially break the production site.
It can decide that even with the execution boundary in place, you know. What matters if it can actually act that out.
All in all, a very sloppily written announcement. Almost as if it was written by—
> ...so make it its own security principal, distinct from the human user?
That presumes the existence of a security context, which this product provides. Where do you configure the security principal otherwise?