While agentic pipelines live in personal configurations, the company cannot see the boundaries of their access or formally assign accountability.
One agent only reads a diff; another has shell access and write access to the repository, build, or deployment. Without a shared system, these differences remain local settings, while a common policy exists only in words.
Permissions are inherited from a person, while actions and approval points do not form a shared log.
Agent identity, limited permissions, separation of read and write access, approval points, isolated runtimes, and a log of actions and decisions.