Identity-bound access
Every action runs under a known identity: for interactive requests, the signed-in user; for background agents, an explicit service account with narrowly defined rights. In both cases the same permission checks apply as for a click in the front end. What the identity may not open, the AI cannot read, cite or summarise either.