Agent access becomes the control layer
Cloudflare’s Agent Access Model is the clearest development today. It proposes task-scoped agents secured through identity brokering, continuous mediation, and stateful trust. In plain English: an agent should not just hold a permanent key. It should prove what job it is doing, get only the access needed for that job, and be checked while it acts. Anthropic’s containment work points in the same direction, framing the engineering problem as capping Claude’s potential blast radius across products. The practical takeaway is immediate. Any agent that touches files, repos, client material, payments, or production systems needs a job-specific access rule before it gets more autonomy. Verdict: test one narrow agent with mediated access before expanding the pattern.