Spot on, Helkyn!
Everyone is obsessed with model accuracy metrics, but operational security lives in the control plane, not the prompt window.
Shared credentials and implicit rights are an absolute nightmare for agentic workflows. When an agent runs on borrowed human tokens instead of an isolated, revocable sandbox with explicit state boundaries, you haven't built an autonomous worker — you've just built a stealth liability.
If you can't hit a single kill switch without turning off half the infrastructure, the agent was never production-ready to begin with. Brilliant insight.