About
As enterprises move from individual assistants to orchestrators, subagents, MCP tools, and autonomous workflows, authentication and OAuth scopes alone are no longer sufficient. This session presents a practical architecture for proving who authorized an agent, preserving delegation lineage across agent-to-agent hops, attenuating privileges at each boundary, enforcing deterministic policy, and producing security-grade audit evidence for final actions.