1 comments โ live from bluesky
The account split is the part I'd watch. One agent identity center role with read paths into workload accounts is useful, but it needs a very boring break-glass path and logs that survive the agent being wrong. How are you scoping write access?