Issue, scope, and revoke in a cascade.
Credentials are issued narrowly, scoped to the task, and revoked in a cascade when an agent is contained, so a compromised or misbehaving agent loses its reach at once.
A credential is issued for what the task needs, not the broadest access available, and is bound to the agent's identity.
When an agent is contained or killed, its credentials and anything delegated from them are revoked together, closing the whole path.
Issue, use and revocation are all sealed to the vault, so the life of every credential is provable.
Related capabilities on the same authorisation layer. Every one is enforced before an action runs and sealed to the Provenance Vault.
Put one workflow behind Xybern and watch every agent action authorised, and sealed to the vault.