Inspired by Moritz Kaminski: an API key answers whether a request is authenticated. It does not answer whether an agent should take a specific action or spend a specific amount. What belongs next: tool scopes, approval rules, spend limits, and an audit trail.
That is the same sentence as last night, said from the other side of the lock. Who holds the keys is ownership. What the key is allowed to do is the job. Mixing those two is how a shop hands a Bot the van and calls it a teammate.
A signed request is not a signed job. Gmail connected is not send. WordPress connected is not publish. Cursor open is not merge. The badge gets you in the door. The desk still writes the ticket: which tool, which action, how much, done-when, and who can pull the plug at 2 a.m.
This is why the email rule is not manners. Resolve the person. Show the draft. Wait for the yes. Log the near-miss. The connector fetches. The human authorizes. Same shape as a spend cap: the Bot can draft against a live inbox and still not touch Send.
If you cannot name the scope, the cap, the yes, and the receipt, you did not hire an agent. You left a signed key on the table and hoped the night would be kind.

Leave a Reply