The restricted access programmes adopted in the period by two frontier companies share a design and, with it, a blind spot: they vet the organisation receiving access, not the use it makes of it.
Vetting happens at the entrance, with analysis of who the company is, what field it operates in and what commitments it makes in writing. After that, access works normally for anyone inside that account.
That means control depends on the approved company maintaining the same discipline internally, with access restricted to the right people and use monitored, which is exactly what the programme can't audit.
It isn't an argument against the format, which is the available answer to a real problem. It's recognition of what it delivers: it reduces the surface of who can ask, without reaching what happens afterwards.
For operators, the transferable lesson applies to any credential granted to a partner: approving access is the start of control rather than the end, and without usage logging and periodic review the approval becomes a rubber stamp.
