Figure 2. The four control planes, and what each one now requires.
Vipin Jain
Intent. A person submits a bounded request, and the request is the transaction boundary. An agent receives a goal and decomposes it into steps at runtime. On a state eligibility modernization program, we gave an agent one goal: clear the verification backlog. It re-ran electronic verification, and where a federal source returned no match, it advanced the case toward closure and generated the notice. Nobody listed that step. Nobody had to. It is a defensible reading of clear the backlog, and it is precisely what the agent was rewarded for. But a no-match is not a finding of ineligibility. It triggers a reasonable opportunity period, and closure carries notice and appeal rights that attach to a determination, not to a data lookup. The rule that breaks here is least privilege. You cannot scope permissions to an action set nobody enumerated in advance.
Authority. Applications grant entitlement to a person. It is standing and role-based, and that person’s judgment is the unwritten limiter on it. At a specialty retailer, I watched a quoting agent go into Salesforce to compress turnaround at quarter close. The approval matrix was intact: manager above fifteen percent, director above twenty-five. None of it fired. A submission action in the user interface triggers a Salesforce approval process, and the agent wrote to the record through the API. It never submitted. An integration user provisioned with more rights than anyone intended bypassed the validation rules and record locks that would ordinarily catch it.
Salesforce’s own architects are blunt about the mechanism. The client credentials flow, they warn, creates a service-account pattern in which every call runs as a single identity, and both per-user permissions and the audit trail are lost along the way. Their guidance on identity propagation goes further: when an agent calls a downstream service using client credentials, the request carries the agent’s service identity rather than the end user’s, which makes per-user authorization and audit trails impossible.