Two announcements from the period address the same problem by different routes: continuous per-action authorisation with zero standing privilege, and governance of assistant use through a corporate identity provider.
The shared problem is familiar to anyone administering a corporate environment. An agent connected to internal tools creates an access path bypassing controls built over years for people and systems.
The answer both products offer is essentially the same: the agent stops using a person's credentials and gets its own identity, with its own scope and expiry, which makes it possible to answer afterwards who authorised what.
The urgency came from research in the same period showing agents frequently reach data nobody explicitly approved, precisely because they inherit the permissions of whoever configured them.
For anyone without such a contract, the principle applies without new products: separate identity, an explicit list of what it may reach, and credentials that expire.
