Roles and least privilege for every agent.
Assign agents to roles with a defined set of capabilities, so authority follows the job rather than the credential. Least privilege becomes the default, not an afterthought.
Group capabilities into roles and assign agents to them, so what an agent may do is explicit and reviewable.
An agent starts with the minimum its role requires and is expanded deliberately, never over-permissioned from the start.
Role boundaries are checked before each action, so an agent cannot act outside its role even if it tries.
Related capabilities on the same authorisation layer. Every one is enforced before an action runs and sealed to the Provenance Vault.
Put one workflow behind Xybern and watch every agent action authorised, and sealed to the vault.